<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:25:39.673-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:28974" version="3" class="patch">
      <metadata>
        <title>ELSA-2015-1002 -- Oracle xen</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="https://oss.oracle.com/pipermail/el-errata/2015-May/005075.html" ref_id="ELSA-2015-1002"/>
        <reference source="CVE" ref_id="CVE-2015-3456" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456"/>
        <description>The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-02T09:04:27-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-03T12:26:56.491-04:00">DRAFT</status_change>
            <status_change date="2015-06-22T04:00:44.896-04:00">INTERIM</status_change>
            <status_change date="2015-07-13T04:00:15.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="All dependent packages of xen">
          <criterion comment="xen-libs is earlier than 0:3.0.3-146.el5_11 for i386" test_ref="oval:org.mitre.oval:tst:137947"/>
          <criterion comment="xen is earlier than 0:3.0.3-146.el5_11 for i386" test_ref="oval:org.mitre.oval:tst:138715"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-146.el5_11 for i386" test_ref="oval:org.mitre.oval:tst:138790"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-146.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138669"/>
          <criterion comment="xen is earlier than 0:3.0.3-146.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138684"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-146.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138927"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-146.el5_11 for ia64" test_ref="oval:org.mitre.oval:tst:138919"/>
          <criterion comment="xen is earlier than 0:3.0.3-146.el5_11 for ia64" test_ref="oval:org.mitre.oval:tst:138642"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-146.el5_11 for ia64" test_ref="oval:org.mitre.oval:tst:138817"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28949" version="3" class="patch">
      <metadata>
        <title>ELSA-2015-1003 -- Oracle kvm-83</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm-83</product>
        </affected>
        <reference source="VENDOR" ref_url="https://oss.oracle.com/pipermail/el-errata/2015-May/005074.html" ref_id="ELSA-2015-1003"/>
        <reference source="CVE" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456" ref_id="CVE-2015-3456"/>
        <description>The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-02T09:04:27-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-03T12:26:56.143-04:00">DRAFT</status_change>
            <status_change date="2015-06-22T04:00:44.808-04:00">INTERIM</status_change>
            <status_change date="2015-07-13T04:00:14.629-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="All dependent packages of kvm-83">
          <criterion comment="kmod-kvm-83 is earlier than 0:272.0.1.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138890"/>
          <criterion comment="kmod-kvm-debug-83 is earlier than 0:272.0.1.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138735"/>
          <criterion comment="kvm-83 is earlier than 0:272.0.1.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138763"/>
          <criterion comment="kvm-qemu-img-83 is earlier than 0:272.0.1.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138901"/>
          <criterion comment="kvm-tools-83 is earlier than 0:272.0.1.el5_11 for x86_64" test_ref="oval:org.mitre.oval:tst:138679"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28823" version="3" class="patch">
      <metadata>
        <title>ELSA-2015-1189 -- kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
          <product>kmod-kvm</product>
          <product>kmod-kvm-debug</product>
          <product>kvm-qemu-img</product>
          <product>kvm-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2015-1189.html" ref_id="ELSA-2015-1189"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3209" ref_id="CVE-2015-3209"/>
        <description>[kvm-83-273.0.1.el5]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch
[kvm-83.273.el5]
- kvm-pcnet-Properly-handle-TX-requests-during-Link-Fail.patch [bz#1225896]
- kvm-pcnet-fix-Negative-array-index-read.patch [bz#1225896]
- kvm-pcnet-force-the-buffer-access-to-be-in-bounds-during.patch [bz#1225896]
- Resolves: bz#1225896
  (EMBARGOED CVE-2015-3209 kvm: qemu: pcnet: multi-tmd buffer overflow in the tx path [rhel-5.11.z)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:38:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:21.765-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:36.707-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:31.041-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-273.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:139819"/>
          <criterion comment="kmod-kvm is earlier than 0:83-273.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:139853"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-273.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:139205"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-273.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:139918"/>
          <criterion comment="kvm-tools is earlier than 0:83-273.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:140090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28647" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3108 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3108.html" ref_id="ELSA-2014-3108"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6657" ref_id="CVE-2012-6657"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9090" ref_id="CVE-2014-9090"/>
        <description>kernel-uek [2.6.32-400.36.13uek] - net: guard tcp_set_keepalive() to tcp
          sockets (Eric Dumazet) [Orabug: 20224099] {CVE-2012-6657} - isofs: Fix unbounded recursion
          when processing relocated directories (Jan Kara) [Orabug: 20224061] {CVE-2014-5471}
          {CVE-2014-5472} - x86_64, traps: Stop using IST for #SS (Andy Lutomirski) [Orabug:
          20224029] {CVE-2014-9090} {CVE-2014-9322}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:24.291-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:35.492-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:31.717-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136785 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:52.836-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:55.958-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136790"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136715"/>
            <criterion comment="ofa-2.6.32-400.36.13.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136763"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136345"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136837"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136775"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136282"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136696"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136720"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136688"/>
            <criterion comment="ofa-2.6.32-400.36.13.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136141"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136565"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136785"/>
            <criterion comment="ofa-2.6.32-400.36.13.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136704"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136346"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136677"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136599"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:135876"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136687"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136699"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136061"/>
            <criterion comment="ofa-2.6.32-400.36.13.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28638" version="3" class="patch">
      <metadata>
        <title>ELSA-2015-0090 -- glibc security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2015-0090.html" ref_id="ELSA-2015-0090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235" ref_id="CVE-2015-0235"/>
        <description>[2.5-123.0.1.el5_11.1]
- Switch to use malloc when the input line is too long [Orabug 19951108]
- Use a /sys/devices/system/cpu/online for _SC_NPROCESSORS_ONLN implementation [Orabug 17642251] (Joe Jin)

[2.5-123.1]
- Fix parsing of numeric hosts in gethostbyname_r (CVE-2015-0235, #1183532).</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-28T12:52:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-29T16:29:55.995-05:00">DRAFT</status_change>
            <status_change date="2015-02-16T04:00:09.919-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:47.380-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-123.0.1.el5_11.1" test_ref="oval:org.mitre.oval:tst:137594"/>
          <criterion comment="glibc-common is earlier than 0:2.5-123.0.1.el5_11.1" test_ref="oval:org.mitre.oval:tst:137078"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-123.0.1.el5_11.1" test_ref="oval:org.mitre.oval:tst:137669"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-123.0.1.el5_11.1" test_ref="oval:org.mitre.oval:tst:137563"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-123.0.1.el5_11.1" test_ref="oval:org.mitre.oval:tst:137321"/>
          <criterion comment="nscd is earlier than 0:2.5-123.0.1.el5_11.1" test_ref="oval:org.mitre.oval:tst:137590"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28616" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-2008-1 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-2008-1.html" ref_id="ELSA-2014-2008-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <description>kernel [2.6.18-400.1.1.0.1] - [net] fix tcp_trim_head() (James Li) [orabug
          14512145, 19219078] - ocfs2: dlm: fix recovery hung (Junxiao Bi) [orabug 13956772] - i386:
          fix MTRR code (Zhenzhong Duan) [orabug 15862649] - [oprofile] x86, mm: Add
          __get_user_pages_fast() [orabug 14277030] - [oprofile] export __get_user_pages_fast()
          function [orabug 14277030] - [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support
          [orabug 14277030] - [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
          - [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030] - [kernel]
          Initialize the local uninitialized variable stats. [orabug 14051367] - [fs] JBD:make jbd
          support 512B blocks correctly for ocfs2. [orabug 13477763] - [x86 ] fix fpu context
          corrupt when preempt in signal context [orabug 14038272] - [mm] fix hugetlb page leak
          (Dave McCracken) [orabug 12375075] - fix ia64 build error due to
          add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use dynamic vcpu_info remap to
          support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0 reset when hvm boot up with
          noapic param - [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris
          Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin)
          [orabug 12561346] - [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
          - [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
          - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646] -
          fix filp_close() race (Joe Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default
          [orabug 67188919] - [xen] check to see if hypervisor supports memory reservation change
          (Chuck Anderson) [orabug 7556514] - [net] Enable entropy for
          bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki) [orabug 10315433] - [NET] Add xen
          pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258] - [mm] Patch shrink_zone to
          yield during severe mempressure events, avoiding hangs and evictions (John Sobecki,Chris
          Mason) [orabug 6086839] - [mm] Enhance shrink_zone patch allow full swap utilization, and
          also be NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919] - fix
          aacraid not to reset during kexec (Joe Jin) [orabug 8516042] - [xen] PVHVM guest with PoD
          crashes under memory pressure (Chuck Anderson) [orabug 9107465] - [xen] PV guest with FC
          HBA hangs during shutdown (Chuck Anderson) [orabug 9764220] - Support 256GB+ memory for pv
          guest (Mukesh Rathor) [orabug 9450615] - fix overcommit memory to use percpu_counter for
          (KOSAKI Motohiro, Guru Anbalagane) [orabug 6124033] - [ipmi] make configurable timeouts
          for kcs of ipmi [orabug 9752208] - [ib] fix memory corruption (Andy Grover) [orabug
          9972346] - [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug
          14795203] - [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug
          14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:15.693-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:34.273-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:30.666-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37975 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:53.422-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:55.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136630"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136655"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136968"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136781"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136860"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136801"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136887"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136762"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136654"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136415"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136711"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-400.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:136961"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136033"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136847"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136743"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136384"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136964"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28577" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1982 -- xorg-x11-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1982.html" ref_id="ELSA-2014-1982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8091" ref_id="CVE-2014-8091"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8092" ref_id="CVE-2014-8092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8093" ref_id="CVE-2014-8093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8095" ref_id="CVE-2014-8095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8096" ref_id="CVE-2014-8096"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8097" ref_id="CVE-2014-8097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8098" ref_id="CVE-2014-8098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8099" ref_id="CVE-2014-8099"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8100" ref_id="CVE-2014-8100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8101" ref_id="CVE-2014-8101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8102" ref_id="CVE-2014-8102"/>
        <description>[1.1.1-48.107.0.1.el5_11]
- Added oracle-enterprise-detect.patch
- Replaced 'Red Hat' in spec file

[1.1.1-48.107]
- CVE-2014-8091 denial of service due to unchecked malloc in client
  authentication (#1168680)
- CVE-2014-8092 integer overflow in X11 core protocol requests when
  calculating memory needs for requests (#1168684)
- CVE-2014-8097 out of bounds access due to not validating length or offset
  values in DBE extension (#1168705)
- CVE-2014-8095 out of bounds access due to not validating length or offset
  values in XInput extension (#1168694)
- CVE-2014-8096 out of bounds access due to not validating length or offset
  values in XC-MISC extension(#1168700)
- CVE-2014-8099 out of bounds access due to not validating length or offset
  values in XVideo extension (#1168710)
- CVE-2014-8100 out of bounds access due to not validating length or offset
  values in Render extension (#1168711)
- CVE-2014-8102 out of bounds access due to not validating length or offset
  values in XFixes extension (#1168714)
- CVE-2014-8101 out of bounds access due to not validating length or offset
  values in RandR extension (#1168713)
- CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests
  when calculating memory needs for requests (#1168688)
- CVE-2014-8098 xorg-x11-server: out of bounds access due to not validating
  length or offset values in GLX extension (#1168707)

[1.1.1-48.104]
- xserver-1.1.1-randr-config-timestamps.patch: Backport timestamp comparison
  fix from upstream RANDR code (#1006076)

[1.1.1-48.103]
- CVE-2013-6424: Fix OOB in trapezoid rasterization</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:20.503-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:32.054-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:28.151-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:137033"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136447"/>
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136905"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136998"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:137015"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136690"/>
          <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136202"/>
          <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.107.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136591"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28492" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3107 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3107.html" ref_id="ELSA-2014-3107"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9090" ref_id="CVE-2014-9090"/>
        <description>[2.6.39-400.215.15]
- isofs: Fix unbounded recursion when processing relocated directories (Jan Kara)  [Orabug: 20224060]  {CVE-2014-5471} {CVE-2014-5472}
- x86_64, traps: Stop using IST for #SS (Andy Lutomirski)  [Orabug: 20224028]  {CVE-2014-9090} {CVE-2014-9322}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:33.730-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:27.021-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:24.239-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136832"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136942"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136702"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136622"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136912"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136881"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136963"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136731"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136952"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136779"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136569"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136803"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28485" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1984 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1984.html" ref_id="ELSA-2014-1984"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8500" ref_id="CVE-2014-8500"/>
        <description>[32:9.9.4-14.0.1.el7_0.1]
- Rebuild to fix libmysqlclient dependency

[32:9.9.4-14.1]
- Fix CVE-2014-8500 (#1171975)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:29.231-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:26.375-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136873 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:23.618-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136036"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136519"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136733"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136925"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137016"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136706"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136834"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136780"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136873"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136911"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136996"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136814"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137028"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136918"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136935"/>
            <criterion comment="bind-chroot is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136900"/>
            <criterion comment="bind-devel is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136970"/>
            <criterion comment="bind-libs is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:137036"/>
            <criterion comment="bind-libs-lite is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136916"/>
            <criterion comment="bind-license is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136571"/>
            <criterion comment="bind-lite-devel is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:137037"/>
            <criterion comment="bind-sdb is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136892"/>
            <criterion comment="bind-sdb-chroot is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:137014"/>
            <criterion comment="bind-utils is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136975"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28482" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3104 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3104.html" ref_id="ELSA-2014-3104"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" ref_id="CVE-2014-3181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1739" ref_id="CVE-2014-1739"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3186" ref_id="CVE-2014-3186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" ref_id="CVE-2014-3688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4027" ref_id="CVE-2014-4027"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4652" ref_id="CVE-2014-4652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4656" ref_id="CVE-2014-4656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" ref_id="CVE-2014-6410"/>
        <description>[2.6.39-400.215.14] 

- HID: magicmouse: sanity check report size in raw_event() callback (Jiri Kosina) [Orabug: 19849355] {CVE-2014-3181} 

- ALSA: control: Protect user controls against concurrent access (Lars-Peter Clausen) [Orabug: 20192542] {CVE-2014-4652} 

- target/rd: Refactor rd_build_device_space + rd_release_device_space (Nicholas Bellinger) [Orabug: 20192517] {CVE-2014-4027} 

- media-device: fix infoleak in ioctl media_enum_entities() (Salva Peiro) [Orabug: 20192501] {CVE-2014-1739} {CVE-2014-1739} 

- udf: Avoid infinite loop when processing indirect ICBs (Jan Kara) [Orabug: 20192449] {CVE-2014-6410} 

- ALSA: control: Make sure that id->index does not overflow (Lars-Peter Clausen) [Orabug: 20192418] {CVE-2014-4656} 

- ALSA: control: Handle numid overflow (Lars-Peter Clausen) [Orabug: 20192376] {CVE-2014-465} 

- HID: picolcd: sanity check report size in raw_event() callback (Jiri Kosina) [Orabug: 20192205] {CVE-2014-3186} 

- net: sctp: fix remote memory pressure from excessive queueing (Daniel Borkmann) [Orabug: 20192059] {CVE-2014-3688}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:22.194-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:25.820-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:23.251-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136810"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136904"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136042"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:137030"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:137027"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136821"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:137031"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136972"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:137007"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136533"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136974"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28414" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1893 -- libXfont security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1893.html" ref_id="ELSA-2014-1893"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0209" ref_id="CVE-2014-0209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0210" ref_id="CVE-2014-0210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0211" ref_id="CVE-2014-0211"/>
        <description>[1.2.2-1.0.6]
- CVE-2014-0209: integer overflow of allocations in font metadata file parsing (bug 1163602, bug 1163601)
- CVE-2014-0210: unvalidated length fields when parsing xfs protocol replies (bug 1163602, bug 1163601)
- CVE-2014-0211: integer overflows calculating memory needs for xfs replies (bug 1163602, bug 1163601)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:33.542-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.256-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:42.900-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libXfont is earlier than 0:1.2.2-1.0.6.el5_11" test_ref="oval:org.mitre.oval:tst:135420"/>
          <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.6.el5_11" test_ref="oval:org.mitre.oval:tst:135545"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28387" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-2008 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-2008.html" ref_id="ELSA-2014-2008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <description>kernel [2.6.18-400.1.1] - [x86] traps: stop using IST for #SS (Petr Matousek)
          [1172809] {CVE-2014-9322}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:23.515-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:21.089-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:18.654-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37898 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:52.405-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:51.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136855"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136468"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136845"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136820"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136856"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136647"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136893"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136947"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136755"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136789"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136924"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-400.1.1.el5" test_ref="oval:org.mitre.oval:tst:136853"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136875"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136713"/>
          <criterion comment="ocfs2-2.6.18-400.1.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:136882"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136836"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136757"/>
          <criterion comment="oracleasm-2.6.18-400.1.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:136880"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28369" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1859 -- mysql55-mysql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql55-mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1859.html" ref_id="ELSA-2014-1859"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2494" ref_id="CVE-2014-2494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4207" ref_id="CVE-2014-4207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4243" ref_id="CVE-2014-4243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4258" ref_id="CVE-2014-4258"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4260" ref_id="CVE-2014-4260"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4274" ref_id="CVE-2014-4274"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4287" ref_id="CVE-2014-4287"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6463" ref_id="CVE-2014-6463"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6464" ref_id="CVE-2014-6464"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6469" ref_id="CVE-2014-6469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6484" ref_id="CVE-2014-6484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6505" ref_id="CVE-2014-6505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6507" ref_id="CVE-2014-6507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6520" ref_id="CVE-2014-6520"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6530" ref_id="CVE-2014-6530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6551" ref_id="CVE-2014-6551"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6555" ref_id="CVE-2014-6555"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6559" ref_id="CVE-2014-6559"/>
        <description>[5.5.40-2]
filter perl(GD) from Requires (perl-gd is not available for RHEL5)
  Resolves: #1160514

[5.5.40-1]
- Rebase to 5.5.40
  Also fixes: CVE-2014-4274 CVE-2014-4287 CVE-2014-6463 CVE-2014-6464
  CVE-2014-6469 CVE-2014-6484 CVE-2014-6505 CVE-2014-6507 CVE-2014-6520
  CVE-2014-6530 CVE-2014-6551 CVE-2014-6555 CVE-2014-6559 CVE-2014-6564
  Resolves: #1160514</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:27.992-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:36.750-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:39.419-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql55-mysql is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135855"/>
          <criterion comment="mysql55-mysql-bench is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135929"/>
          <criterion comment="mysql55-mysql-devel is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:136013"/>
          <criterion comment="mysql55-mysql-libs is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135284"/>
          <criterion comment="mysql55-mysql-server is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135869"/>
          <criterion comment="mysql55-mysql-test is earlier than 0:5.5.40-2.el5" test_ref="oval:org.mitre.oval:tst:135688"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28309" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3088 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3088.html" ref_id="ELSA-2014-3088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" ref_id="CVE-2014-3687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" ref_id="CVE-2014-3673"/>
        <description>[2.6.39-400.215.13]
- net: sctp: fix panic on duplicate ASCONF chunks (Daniel Borkmann)  [Orabug: 20010591]  {CVE-2014-3687}
- net: sctp: fix skb_over_panic when receiving malformed ASCONF chunks (Daniel Borkmann)  [Orabug: 20010578]  {CVE-2014-3673}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:42.844-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.180-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:45.056-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135364"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135579"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:134934"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:134717"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135663"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135400"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135604"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135548"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135659"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135634"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135564"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135144"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28287" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0122 -- sudo security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0122.html" ref_id="ELSA-2010-0122"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0426" ref_id="CVE-2010-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0427" ref_id="CVE-2010-0427"/>
        <description>[1.6.9p17-6]
- added patches for CVE-2010-0426 and CVE-2010-0427
  Resolves: #567689</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:55.743-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:45.184-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:41.963-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:23:24.481-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:23:24.481-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.6.9p17-6.el5_4" test_ref="oval:org.mitre.oval:tst:135212"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28276" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0124 -- systemtap security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0124.html" ref_id="ELSA-2010-0124"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4273" ref_id="CVE-2009-4273"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0411" ref_id="CVE-2010-0411"/>
        <description>[0.9.7-5.3]
- rhbz556564-2: CVE-2009-4273 cont'd aka CVE-2010-0412
- rhbz559719: CVE-2010-0411
- pr11286: stap-client --server operation

[0.9.7-5.2]
- rhbz556564: CVE-2009-4273</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:16.089-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:44.919-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:41.855-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:14:21.742-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:14:21.742-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="systemtap is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:135287"/>
          <criterion comment="systemtap-client is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:134305"/>
          <criterion comment="systemtap-initscript is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:134880"/>
          <criterion comment="systemtap-runtime is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:135286"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:134554"/>
          <criterion comment="systemtap-server is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:135149"/>
          <criterion comment="systemtap-testsuite is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:135301"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28271" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0198 -- openldap security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0198.html" ref_id="ELSA-2010-0198"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3767" ref_id="CVE-2009-3767"/>
        <description>[2.3.43-12]
- updated spec file, so the compat-libs linking patch applies
  correctly

[2.3.43-11]
- backported patch to handle null character in TLS
  certificates (#560912)

[2.3.43-10]
- updated chase-referral patch to compile cleanly
- updated init script (#562714)

[2.3.43-9]
- updated ldap.sysconf to include SLAPD_LDAP, SLAPD_LDAPS and
  SLAPD_LDAPI options (#559520)

[2.3.43-8]
- fixed connection freeze when TLSVerifyClient = allow (#509230)

[2.3.43-7]
- fixed chasing referrals in libldap (#510522)

[2.3.43-6]
- fixed possible double free() in rwm overlay (#495628)
- updated slapd man page and slapcat usage string (#468206)
- updated default config for slapd - deleted syncprov module (#466937)
- fixed migration tools autofs generated format (#460331)
- fixed migration tools numbers detection in /etc/shadow (#113857)
- fixed migration tools base ldif (#104585)

[2.3.43-5]
- implementation of limit adjustment before starting slapd (#527313)
- init script no longer executes script in /tmp (#483356)
- slapd not starting with ldap:/// every time (#481003)
- delay between TERM and KILL when shutting down slapd (#452064)

[2.3.43-4]
- fixed compat libs linking (#503734)
- activated lightweight dispatcher feature (#507276)
- detection of timeout after failed result (#495701</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:11.425-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:44.732-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:41.735-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:28:17.123-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:28:17.123-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:134661"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5" test_ref="oval:org.mitre.oval:tst:135256"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:135114"/>
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:135197"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:134281"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:135272"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:135076"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28269" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0339 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0339.html" ref_id="ELSA-2010-0339"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0082" ref_id="CVE-2010-0082"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0084" ref_id="CVE-2010-0084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0085" ref_id="CVE-2010-0085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0088" ref_id="CVE-2010-0088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0091" ref_id="CVE-2010-0091"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0092" ref_id="CVE-2010-0092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0093" ref_id="CVE-2010-0093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0094" ref_id="CVE-2010-0094"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0095" ref_id="CVE-2010-0095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0837" ref_id="CVE-2010-0837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0838" ref_id="CVE-2010-0838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0840" ref_id="CVE-2010-0840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0845" ref_id="CVE-2010-0845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0847" ref_id="CVE-2010-0847"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0848" ref_id="CVE-2010-0848"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" ref_id="CVE-2009-3555"/>
        <description>[1:1.6.0.0-1.11.b16.0.1.el5]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.11.b16.el5]
- Remove javaws alternative due to conflict with java-1.6.0-sun's alternatives

[1:1.6.0-1.10.b16]
- Update to openjdk build b16
- Update to icedtea6-1.6
- Added tzdata-java requirement
- Added autoconf and automake build requirement
- Added tzdata-java requirement
- Added java-1.6.0-openjdk-gcc-stack-markings.patch
- Added java-1.6.0-openjdk-memory-barriers.patch
- Added java-1.6.0-openjdk-jar-misc.patch
- Added java-1.6.0-openjdk-linux-separate-debuginfo.patch
- Added java-1.6.0-openjdk-securitypatches-20100323.patch
- Added STRIP_KEEP_SYMTAB=libjvm* to install section, fix bz530402
- Resolves: rhbz#576124

[1:1.6.0-1.8.b09]
- Added java-1.6.0-openjdk-debuginfo.patch
- Added java-1.6.0-openjdk-elf-debuginfo.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:06.629-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:43.520-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:41.220-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:44:53.134-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:44:53.134-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.11.b16.0.1.el5" test_ref="oval:org.mitre.oval:tst:134652"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.11.b16.0.1.el5" test_ref="oval:org.mitre.oval:tst:134876"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.11.b16.0.1.el5" test_ref="oval:org.mitre.oval:tst:134265"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.11.b16.0.1.el5" test_ref="oval:org.mitre.oval:tst:135245"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.11.b16.0.1.el5" test_ref="oval:org.mitre.oval:tst:135239"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28263" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3094 -- bash security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3094.html" ref_id="ELSA-2014-3094"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6277" ref_id="CVE-2014-6277"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6278" ref_id="CVE-2014-6278"/>
        <description>[3.2-33.4.0.1]
- Fix segfaults from CVE-2014-6277 and CVE-2014-6278 completely. [orabug 19905421]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:25.441-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:27.431-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:31.308-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="bash is earlier than 0:3.2-33.el5_11.4.0.1" test_ref="oval:org.mitre.oval:tst:136037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28261" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1974 -- rpm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1974.html" ref_id="ELSA-2014-1974"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6435" ref_id="CVE-2013-6435"/>
        <description>[4.4.2.3-36.0.1]
- Add missing files in /usr/share/doc/

[4.8.0-36]
- Fix warning when applying the patch for #1163057

[4.8.0-35]
- Fix race condidition where unchecked data is exposed in the file system
  (CVE-2013-6435)(#1163057)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:27.743-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:16.989-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:13.629-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:137129"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:137144"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136804"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136907"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136988"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136610"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136800"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136992"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137134"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137118"/>
            <criterion comment="rpm-cron is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136805"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136823"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137097"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137051"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28260" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0109 -- mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0109.html" ref_id="ELSA-2010-0109"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4019" ref_id="CVE-2009-4019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4028" ref_id="CVE-2009-4028"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4030" ref_id="CVE-2009-4030"/>
        <description>[5.0.77-4.2]
- Add fixes for CVE-2009-4019, CVE-2009-4028, CVE-2009-4030
Resolves: #556505
- Use non-expired certificates for SSL testing (upstream bug 50702)
- Emit explicit error message if user tries to build RPM as root
- Add comment suggesting disabling symbolic links in /etc/my.cnf</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:15.113-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:43.216-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:41.052-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:46:47.328-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:46:47.328-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:135187"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:134325"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:134821"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:135208"/>
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:135306"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28255" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0019 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0019.html" ref_id="ELSA-2010-0019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4567" ref_id="CVE-2007-4567"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4536" ref_id="CVE-2009-4536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4537" ref_id="CVE-2009-4537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4538" ref_id="CVE-2009-4538"/>
        <description>[2.6.18-164.10.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change 
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb ( John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN  [orabug 7689332]
- [NET] Add xen pv/bonding  netconsole support (Tina yang) [orabug 6993043] 
  [bz 7258]
- [MM] shrink zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang) 
  [orabug 7579314]
- FP register state is corrupted during the handling a SIGSEGV (Chuck Anderson)
  [orabug 7708133]

[2.6.18-164.10.1.el5]
- [net] e1000, r9169: fix rx length check errors (Cong Wang ) [550914 550915]
- [net] e1000e: fix rx length check errors (Amerigo Wang ) [551222 551223]
- [net] ipv6: fix ipv6_hop_jumbo remote system crash (Amerigo Wang ) [548642 548643] {CVE-2007-4567}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:50.145-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:42.794-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:40.799-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:13:19.215-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:13:19.215-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135322"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.10.1.0.1.el5-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135006"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.10.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135089"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135107"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135280"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134923"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135231"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135143"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134974"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135262"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135220"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.10.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135379"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.10.1.0.1.el5PAE-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:134461"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.10.1.0.1.el5debug-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135294"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.10.1.0.1.el5xen-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135161"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.10.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135341"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.10.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135170"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.10.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28253" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0054 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0054.html" ref_id="ELSA-2010-0054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4355" ref_id="CVE-2009-4355"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409" ref_id="CVE-2009-2409"/>
        <description>[0.9.8e-12.1]
- fix CVE-2009-2409 - drop MD2 algorithm from EVP tables (#510197)
- fix CVE-2009-4355 - do not leak memory when CRYPTO_cleanup_all_ex_data()
  is called prematurely by application (#546707)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:57.013-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:42.629-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:40.687-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:48:10.821-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:48:10.821-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:134668"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:135242"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:135361"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28248" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0528 -- avahi security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0528.html" ref_id="ELSA-2010-0528"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0758" ref_id="CVE-2009-0758"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2244" ref_id="CVE-2010-2244"/>
        <description>[0.6.16-9.el5]
- Related: #609318 
- Fixes CVE-2010-2244

[0.6.16-8.el5]
- Related: #609318 
- Fixes CVE-2010-2244</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:04.899-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:42.373-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:40.550-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:42:29.537-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:42:29.537-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="avahi is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134893"/>
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134550"/>
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134316"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134712"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134755"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134726"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134916"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134110"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:135070"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:135008"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.16-9.el5_5" test_ref="oval:org.mitre.oval:tst:134327"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28238" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0615 -- libvirt security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0615.html" ref_id="ELSA-2010-0615"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2239" ref_id="CVE-2010-2239"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2242" ref_id="CVE-2010-2242"/>
        <description>[0.6.3-33.0.1.el5_5.3]
- Replaced docs/et.png in tarball

[0.6.3-33.el5_5.3]
- Explicitly set qcow2 backing store format (CVE-2010-2239)
- Remap privileged source ports from guests behind NAT (CVE-2010-2242)
- Eliminate memory leak in xenUnifiedDomainInfoListFree (rhbz 619711)

[0.6.3-33.el5_5.2]
- Fix discrepancy between xm list and virsh list (rhbz 618200)
- Set a stable &amp; high MAC addr for guest TAP devices on host (rhbz 617243)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:56.565-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:42.073-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:40.436-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:43:47.766-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:43:47.766-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.6.3-33.0.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134631"/>
          <criterion comment="libvirt-devel is earlier than 0:0.6.3-33.0.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134539"/>
          <criterion comment="libvirt-python is earlier than 0:0.6.3-33.0.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134808"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28222" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0398 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0398.html" ref_id="ELSA-2010-0398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0307" ref_id="CVE-2010-0307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0410" ref_id="CVE-2010-0410"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0730" ref_id="CVE-2010-0730"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1085" ref_id="CVE-2010-1085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1086" ref_id="CVE-2010-1086"/>
        <description>[2.6.18-194.3.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [nfs] -revert return code check to avoid EIO (Chuck Lever, Guru Anbalagane) 
  [Orabug 9448515]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) [orabug 9504524]
- [mm] Set hugepages dirty bit so vm.drop_caches does not corrupt (John Sobecki)
  [orabug 9461825]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()

[2.6.18-194.3.1.el5]
- [net] bnx2: fix lost MSI-X problem on 5709 NICs (John Feeney) [587799 511368]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:54.824-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:41.530-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:40.208-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:03:02.049-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:03:02.049-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134710"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.3.1.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134847"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.3.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135086"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134836"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134798"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134703"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134924"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134138"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134154"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134182"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134931"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134228"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.3.1.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134563"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.3.1.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:135168"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.3.1.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:135074"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.3.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135098"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.3.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135100"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.3.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28217" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0792 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0792.html" ref_id="ELSA-2010-0792"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3904" ref_id="CVE-2010-3904"/>
        <description>[2.6.18-194.17.4.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) 
  [orabug 9504524]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)
  [orabug 9245919]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]

[2.6.18-194.17.4.el5]
- [net] rds: fix local privilege escalation (Eugene Teo) [642897 642898] {CVE-2010-3904}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:51.991-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:41.393-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:40.112-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:33:07.092-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:33:07.092-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134679"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.4.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134833"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.4.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134669"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134778"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134653"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134775"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134815"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134789"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134894"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134845"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134871"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134886"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.4.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134872"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.4.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134889"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.4.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134802"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.4.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134885"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.4.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134807"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.4.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134468"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28216" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0976 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0976.html" ref_id="ELSA-2010-0976"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3613" ref_id="CVE-2010-3613"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614" ref_id="CVE-2010-3614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3762" ref_id="CVE-2010-3762"/>
        <description>[30:9.3.6-4.P1.3]
- fixes for CVE-2010-3762, CVE-2010-3613 and CVE-2010-3614</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:48.101-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:41.205-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:40.005-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:43:18.896-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:43:18.896-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134795"/>
          <criterion comment="bind-chroot is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134811"/>
          <criterion comment="bind-devel is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134529"/>
          <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134353"/>
          <criterion comment="bind-libs is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134741"/>
          <criterion comment="bind-sdb is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134537"/>
          <criterion comment="bind-utils is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134619"/>
          <criterion comment="caching-nameserver is earlier than 0:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134711"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28210" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0675 -- sudo security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0675.html" ref_id="ELSA-2010-0675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2956" ref_id="CVE-2010-2956"/>
        <description>[1.7.2p1-8]
- added patch for CVE-2010-2956 (#628628)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:00.396-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:41.058-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:39.928-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:13:39.269-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:13:39.269-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-8.el5_5" test_ref="oval:org.mitre.oval:tst:134218"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28200" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0025 -- gcc security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gcc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0025.html" ref_id="ELSA-2011-0025"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0831" ref_id="CVE-2010-0831"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2322" ref_id="CVE-2010-2322"/>
        <description>[4.1.2-50.el5]
- fix up fastjar directory traversal bugs (CVE-2010-0831)

[4.1.2-49.el5]
- fix ICE in set_uids_in_ptset (#605803)
- fix ICE in make_rtl_for_nonlocal_decl (#582682, #508735, #503565,
  PR c++/33094)
- dont build gcjwebplugin (#596097)
- fix IPP handling in libgcj (#578382)
- document -print-multi-os-directory (#529659, PR other/25507)
- fix ICE in output_die with function local types (#527510, PR debug/41063)
- speed up locale::locale() ctor if _S_global hasnt been changed
  (#635708, PR libstdc++/40088)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:07.113-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:39.089-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:38.835-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:28:11.960-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:28:11.960-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gcc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134752"/>
          <criterion comment="cpp is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:133762"/>
          <criterion comment="gcc-c++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134651"/>
          <criterion comment="gcc-gfortran is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134494"/>
          <criterion comment="gcc-gnat is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134346"/>
          <criterion comment="gcc-java is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134595"/>
          <criterion comment="gcc-objc++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134557"/>
          <criterion comment="gcc-objc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134713"/>
          <criterion comment="libgcc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134647"/>
          <criterion comment="libgcj is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134432"/>
          <criterion comment="libgcj-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134695"/>
          <criterion comment="libgcj-src is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:133884"/>
          <criterion comment="libgfortran is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134560"/>
          <criterion comment="libgnat is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134307"/>
          <criterion comment="libmudflap is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134655"/>
          <criterion comment="libmudflap-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134328"/>
          <criterion comment="libobjc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134551"/>
          <criterion comment="libstdc++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134565"/>
          <criterion comment="libstdc++-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:134603"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28199" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0017 -- Oracle Linux 5.6 kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0017.html" ref_id="ELSA-2011-0017"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3296" ref_id="CVE-2010-3296"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3877" ref_id="CVE-2010-3877"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4072" ref_id="CVE-2010-4072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4073" ref_id="CVE-2010-4073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4075" ref_id="CVE-2010-4075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4080" ref_id="CVE-2010-4080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4081" ref_id="CVE-2010-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4158" ref_id="CVE-2010-4158"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4238" ref_id="CVE-2010-4238"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4243" ref_id="CVE-2010-4243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4255" ref_id="CVE-2010-4255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4263" ref_id="CVE-2010-4263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4343" ref_id="CVE-2010-4343"/>
        <description>This update fixes the following security issues:

* A NULL pointer dereference flaw was found in the igb driver in the Linux
kernel. If both the Single Root I/O Virtualization (SR-IOV) feature and
promiscuous mode were enabled on an interface using igb, it could result in
a denial of service when a tagged VLAN packet is received on that
interface. (CVE-2010-4263, Important)

* A missing sanity check was found in vbd_create() in the Xen hypervisor
implementation. As CD-ROM drives are not supported by the blkback back-end
driver, attempting to use a virtual CD-ROM drive with blkback could trigger
a denial of service (crash) on the host system running the Xen hypervisor.
(CVE-2010-4238, Moderate)

* A flaw was found in the Linux kernel execve() system call implementation.
A local, unprivileged user could cause large amounts of memory to be
allocated but not visible to the OOM (Out of Memory) killer, triggering a
denial of service. (CVE-2010-4243, Moderate)

* A flaw was found in fixup_page_fault() in the Xen hypervisor
implementation. If a 64-bit para-virtualized guest accessed a certain area
of memory, it could cause a denial of service on the host system running
the Xen hypervisor. (CVE-2010-4255, Moderate)

* A missing initialization flaw was found in the bfa driver used by Brocade
Fibre Channel Host Bus Adapters. A local, unprivileged user could use this
flaw to cause a denial of service by reading a file in the
"/sys/class/fc_host/host#/statistics/" directory. (CVE-2010-4343, Moderate)

* Missing initialization flaws in the Linux kernel could lead to
information leaks. (CVE-2010-3296, CVE-2010-3877, CVE-2010-4072,
CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4158,
Low)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:59.409-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:38.555-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:38.584-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:47:36.902-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:47:36.902-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134749"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134719"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134533"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134536"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134617"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134607"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134718"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134613"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134582"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134671"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134469"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:134598"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133755"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134294"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134401"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134414"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134481"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134220"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28192" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-2025 -- ntp security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ntp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-2025.html" ref_id="ELSA-2014-2025"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9293" ref_id="CVE-2014-9293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9294" ref_id="CVE-2014-9294"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9295" ref_id="CVE-2014-9295"/>
        <description>[4.2.2p1-18.el5]
- don't generate weak control key for resolver (CVE-2014-9293)
- don't generate weak MD5 keys in ntp-keygen (CVE-2014-9294)
- fix buffer overflows via specially-crafted packets (CVE-2014-9295)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:29.731-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:16.039-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:11.392-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="ntp is earlier than 0:4.2.2p1-18.el5_11" test_ref="oval:org.mitre.oval:tst:136092"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28190" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0108 -- NetworkManager security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>NetworkManager</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0108.html" ref_id="ELSA-2010-0108"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4144" ref_id="CVE-2009-4144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4145" ref_id="CVE-2009-4145"/>
        <description>[1:0.7.0-9.el5_4]
- Ensure a connection is not used after its CA certificate has been deleted
- Resolves: CVE-2009-4144
- Fix possible information disclosure by nm-connection-editor
- Resolves: CVE-2009-4145</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:52.396-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:37.834-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:38.181-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:00:15.031-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:00:15.031-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="NetworkManager is earlier than 0:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:134597"/>
          <criterion comment="NetworkManager-devel is earlier than 0:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:135293"/>
          <criterion comment="NetworkManager-glib is earlier than 0:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:135316"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 0:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:134864"/>
          <criterion comment="NetworkManager-gnome is earlier than 0:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:134853"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28188" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0768 -- java-1.6.0-openjdk security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0768.html" ref_id="ELSA-2010-0768"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3541" ref_id="CVE-2010-3541"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3548" ref_id="CVE-2010-3548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3549" ref_id="CVE-2010-3549"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3551" ref_id="CVE-2010-3551"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3553" ref_id="CVE-2010-3553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3554" ref_id="CVE-2010-3554"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3557" ref_id="CVE-2010-3557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3561" ref_id="CVE-2010-3561"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3562" ref_id="CVE-2010-3562"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3564" ref_id="CVE-2010-3564"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3565" ref_id="CVE-2010-3565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3567" ref_id="CVE-2010-3567"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3568" ref_id="CVE-2010-3568"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3569" ref_id="CVE-2010-3569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3573" ref_id="CVE-2010-3573"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3574" ref_id="CVE-2010-3574"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" ref_id="CVE-2009-3555"/>
        <description>[1.6.0.0-1.16.b17.0.1.el5]
- Add oracle-enterprise.patch

[1.6.0.0-1.16.b17.el5]
- Updated 1.7.5 tarball (contains additional security fixes)
- Resolves: bz639951

[1.6.0.0-1.15.b17.el5]
- Rebuild
- Resolves: bz639951

[1.6.0.0-1.14.b17.el5]
- Synched with el6 branch
- Updated to IcedTea 1.7.5
- Resolves: bz639951
- Also resolves 619800 and 621303</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:07.491-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:36.245-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:37.644-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:56:40.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:56:40.034-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.16.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134323"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.16.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134477"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.16.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134956"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.16.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134911"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.16.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134959"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28185" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0430 -- postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0430.html" ref_id="ELSA-2010-0430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1169" ref_id="CVE-2010-1169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1170" ref_id="CVE-2010-1170"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1975" ref_id="CVE-2010-1975"/>
        <description>[8.4.4-1.el5_5.1]
- Update to PostgreSQL 8.4.4, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-4.html
  including fixes for CVE-2010-1169 and CVE-2010-1170
Resolves: #586060</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:10.302-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:35.866-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:37.432-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:56:33.511-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:56:33.511-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql84 is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134393"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135123"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135069"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134967"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135124"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134594"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134739"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135082"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135021"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135095"/>
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135049"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134981"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28184" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0018 -- dbus security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0018.html" ref_id="ELSA-2010-0018"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1189" ref_id="CVE-2009-1189"/>
        <description>[1.1.2-12.el5_4.1]
- CVE-2009-1189 dbus: invalid fix for CVE-2008-3834</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:02.413-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:35.656-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:37.336-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:53:15.495-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:53:15.495-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dbus is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:135266"/>
          <criterion comment="dbus-devel is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:135224"/>
          <criterion comment="dbus-libs is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:134488"/>
          <criterion comment="dbus-x11 is earlier than 0:1.1.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:135141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28180" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0382 -- xorg-x11-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0382.html" ref_id="ELSA-2010-0382"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1166" ref_id="CVE-2010-1166"/>
        <description>[1.1.1-48.76.0.1.el5_5.1 ]
- Added oracle-enterprise-detect.patch
- Replaced 'Red Hat' in spec file

[1.1.1-48.76.1]
- xserver-1.1.1-mod-macro-parens.patch: Fix insufficient parentheses in
  Render and arc computation code. (#495733)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:18.112-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:35.141-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:37.126-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:27:28.683-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:27:28.683-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135109"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135133"/>
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135169"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134925"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134790"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134986"/>
          <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135103"/>
          <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.0.1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135155"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28175" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0429 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0429.html" ref_id="ELSA-2011-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4346" ref_id="CVE-2010-4346"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0521" ref_id="CVE-2011-0521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0710" ref_id="CVE-2011-0710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1010" ref_id="CVE-2011-1010"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1090" ref_id="CVE-2011-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1478" ref_id="CVE-2011-1478"/>
        <description>[2.6.18-238.9.1.0.1.el5]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- fix missing aio_complete() in end_io (Joel Becker) [orabug 10365195]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [nfs] too many getattr and access calls after direct I/O [orabug 9348191]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:51.620-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:34.794-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.897-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:01:17.684-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:01:17.684-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134032"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.9.1.0.1.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134119"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.9.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133760"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134123"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134071"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133592"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133656"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133414"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133954"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134084"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134132"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133140"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.9.1.0.1.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134075"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.9.1.0.1.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134104"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.9.1.0.1.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133877"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.9.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133235"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.9.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133535"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.9.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134094"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28165" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1422 -- openswan security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1422.html" ref_id="ELSA-2011-1422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4073" ref_id="CVE-2011-4073"/>
        <description>[2.6.32-4.4]
Resolves: #748969 CVE-2011-4073 updated patch by upstream

[2.6.32-4.3]
Resolves: #748969 CVE-2011-4073</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:13.029-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.779-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.319-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:15:47.384-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:15:47.384-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:133284"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:133360"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:133191"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:133254"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28163" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0327 -- subversion security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0327.html" ref_id="ELSA-2011-0327"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0715" ref_id="CVE-2011-0715"/>
        <description>[1.6.11-7.3]
- add fix for svnadmin hotcopy (#681522)

[1.6.11-7.2]
- add security fix for CVE-2011-0715 (#681171)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:41.831-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.667-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.224-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:50:25.233-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:50:25.233-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:134091"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:134221"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:134169"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:133783"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:133991"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:133915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28161" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1815 -- icu security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>icu</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1815.html" ref_id="ELSA-2011-1815"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4599" ref_id="CVE-2011-4599"/>
        <description>[4.2.1-9.1]

- Resolves: rhbz#766539 CVE-2011-4599 localeID overflow</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:28.837-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.464-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.110-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:57:17.000-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:57:17.000-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="icu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:132863"/>
            <criterion comment="libicu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:133134"/>
            <criterion comment="libicu-devel is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:133051"/>
            <criterion comment="libicu-doc is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:133137"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="icu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:133053"/>
            <criterion comment="libicu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:132537"/>
            <criterion comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:132828"/>
            <criterion comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:132916"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28160" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0793 -- glibc security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0793.html" ref_id="ELSA-2010-0793"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3856" ref_id="CVE-2010-3856"/>
        <description>[2.5-49.el5_5.7]
- Require suid bit on audit objects in privileged programs (#645677,
  CVE-2010-3856)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:49.913-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.338-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.022-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:29:09.564-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:29:09.564-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:134793"/>
          <criterion comment="glibc-common is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:134855"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:134696"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:134890"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:134374"/>
          <criterion comment="nscd is earlier than 0:2.5-49.el5_5.7" test_ref="oval:org.mitre.oval:tst:134304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28158" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2029 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2029.html" ref_id="ELSA-2011-2029"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1833" ref_id="CVE-2011-1833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2484" ref_id="CVE-2011-2484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2496" ref_id="CVE-2011-2496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2723" ref_id="CVE-2011-2723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2898" ref_id="CVE-2011-2898"/>
        <description>[2.6.32-200.20.1.el6uek] - af_packet: prevent information leak {CVE-2011-2898}
          - gro: Only reset frag0 when skb can be pulled {CVE-2011-2723} - vm: fix vm_pgoff wrap in
          stack expansion {CVE-2011-2496} - vm: fix vm_pgoff wrap in upward expansion
          {CVE-2011-2496} - taskstats: don't allow duplicate entries in listener mode
          {CVE-2011-2484} - Ecryptfs: Add mount option to check uid of device being mounted
          {CVE-2011-1833}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:12.632-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:32.953-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.780-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36772 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:55.892-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:49.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133125"/>
            <criterion comment="ofa-2.6.32-200.20.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132745"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133435"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133031"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133104"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133436"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133407"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133393"/>
            <criterion comment="ofa-2.6.32-200.20.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:133046"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133428"/>
            <criterion comment="ofa-2.6.32-200.20.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132726"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133233"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133016"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133392"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:132879"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133184"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133229"/>
            <criterion comment="ofa-2.6.32-200.20.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133317"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28157" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2025 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2025.html" ref_id="ELSA-2011-2025"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576" ref_id="CVE-2011-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1898" ref_id="CVE-2011-1898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2183" ref_id="CVE-2011-2183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2491" ref_id="CVE-2011-2491"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2492" ref_id="CVE-2011-2492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2495" ref_id="CVE-2011-2495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2497" ref_id="CVE-2011-2497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2517" ref_id="CVE-2011-2517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2695" ref_id="CVE-2011-2695"/>
        <description>[2.6.32-200.19.1.el6uek] - Apply new fix for CVE-2011-1576.
          [2.6.32-200.18.1.el6uek] - Revert 'proc: fix a race in do_io_accounting'
          [2.6.32-200.17.1.el6uek] - net: Fix memory leak/corruption on VLAN GRO_DROP
          {CVE-2011-1576} - iommu-api: Extension to check for interrupt remapping {CVE-2011-1898} -
          KVM: IOMMU: Disable device assignment without interrupt remapping {CVE-2011-1898} - ext4:
          Fix max file size and logical block counting of extent format file {CVE-2011-2695} -
          nl80211: fix overflow in ssid_len {CVE-2011-2517} - Bluetooth: Prevent buffer overflow in
          l2cap config request {CVE-2011-2497} - proc: fix a race in do_io_accounting()
          {CVE-2011-2495} - proc: restrict access to /proc/PID/io {CVE-2011-2495} - Bluetooth: l2cap
          and rfcomm: fix 1 byte infoleak to userspace {CVE-2011-2492} - NLM: Don't hang forever on
          NLM unlock requests {CVE-2011-2491} - ksm: fix NULL pointer dereference in
          scan_get_next_rmap_item() {CVE-2011-2183}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:36.061-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:32.774-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.556-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:133312 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:52.084-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:48.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133383"/>
            <criterion comment="ofa-2.6.32-200.19.1.el5uek is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133565"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133267"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133551"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133597"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:132786"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133475"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133446"/>
            <criterion comment="ofa-2.6.32-200.19.1.el5uekdebug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133440"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:132623"/>
            <criterion comment="ofa-2.6.32-200.19.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133312"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133536"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133589"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133618"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133324"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133609"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133421"/>
            <criterion comment="ofa-2.6.32-200.19.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28151" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1089 -- systemtap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1089.html" ref_id="ELSA-2011-1089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2503" ref_id="CVE-2011-2503"/>
        <description>[1.3-9]
- bz716489 (patch)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:42.668-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:32.141-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.234-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:18:32.487-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:18:32.487-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="systemtap is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:133349"/>
          <criterion comment="systemtap-client is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:133308"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:133501"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:132892"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:132662"/>
          <criterion comment="systemtap-server is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:133453"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:132689"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28149" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0199 -- krb5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0199.html" ref_id="ELSA-2011-0199"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0281" ref_id="CVE-2011-0281"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0282" ref_id="CVE-2011-0282"/>
        <description>- add upstream patch to fix hang or crash in the KDC when using the LDAP kdb
  backend (CVE-2011-0281, CVE-2011-0282, #671096)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:42.279-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:31.991-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.148-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:08:48.147-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:08:48.147-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:134145"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:134621"/>
          <criterion comment="krb5-libs is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:134544"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:134229"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:134610"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:134623"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28144" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0862 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0862.html" ref_id="ELSA-2011-0862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1752" ref_id="CVE-2011-1752"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1783" ref_id="CVE-2011-1783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1921" ref_id="CVE-2011-1921"/>
        <description>[1.6.11-2.4]
- add security fixes for CVE-2011-1752, CVE-2011-1783, CVE-2011-1921 (#709220)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:44.555-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:30.583-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.638-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:49:57.899-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:49:57.899-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133133"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133761"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:132934"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133798"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133602"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133663"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133427"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133108"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133606"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133147"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133725"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133807"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133765"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133691"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133642"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28143" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0163 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0163.html" ref_id="ELSA-2011-0163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4526" ref_id="CVE-2010-4526"/>
        <description>[2.6.18-238.1.1.0.1.el5]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- fix missing aio_complete() in end_io (Joel Becker) [orabug 10365195]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [nfs] too many getattr and access calls after direct I/O [orabug 9348191]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)

[2.6.18-238.1.1.el5]
- [scsi] megaraid: give FW more time to recover from reset (Tomas Henzl) [667141 665427]
- [fs] gfs2: fix statfs error after gfs2_grow (Robert S Peterson) [666792 660661]
- [mm] prevent file lock corruption using popen(3) (Larry Woodman) [667050 664931]
- [net] sctp: fix panic from bad socket lock on icmp error (Neil Horman) [665476 665477] {CVE-2010-4526}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:40.328-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:30.322-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.521-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:59:34.428-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:59:34.428-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134657"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.1.1.0.1.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134037"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.1.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134553"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134641"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134611"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133932"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134732"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134572"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134581"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134733"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134567"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134705"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.1.1.0.1.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134546"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.1.1.0.1.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134658"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.1.1.0.1.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134514"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.1.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134588"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.1.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134674"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.1.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134313"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28141" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0273 -- curl security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0273.html" ref_id="ELSA-2010-0273"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0734" ref_id="CVE-2010-0734"/>
        <description>[7.15.5-9]
- http://curl.haxx.se/docs/adv_20100209.html (#565408)

[7.15.5-8]
- mention lack of IPv6, FTPS and LDAP support while using a socks proxy
  (#473128)
- avoid tight loop if an upload connection is broken (#479967)
- add options --ftp-account and --ftp-alternative-to-user to program help
  (#517084)
- fix crash when reusing connection after negotiate-auth (#517199)
- support for CRL loading from a PEM file (#532069)

[7.15.5-7]
- sync patch for CVE-2007-0037 with 5.3.Z
Related: #485290

[7.15.5-6]
- fix CVE-2009-2417
Resolves: #516258

[7.15.5-5]
- forwardport one hunk from upstream curl-7.15.1
Related: #485290

[7.15.5-4]
- fix hunk applied to wrong place due to nonzero patch fuzz
Related: #485290

[7.15.5-3]
- fix CVE-2007-0037
Resolves: #485290</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:19.171-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:30.067-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.417-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:35:34.358-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:35:34.358-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="curl is earlier than 0:7.15.5-9.el5" test_ref="oval:org.mitre.oval:tst:134878"/>
          <criterion comment="curl-devel is earlier than 0:7.15.5-9.el5" test_ref="oval:org.mitre.oval:tst:135121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28140" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0556 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0556.html" ref_id="ELSA-2010-0556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2755" ref_id="CVE-2010-2755"/>
        <description>firefox:

[3.6.7-3.0.1.el5]
- Add firefox-oracle-default-prefs.js and firefox-oracle-default-bookmarks.html
  and remove the corresponding Red Hat ones

[3.6.7-3]
- Rebuild

xulrunner:

[1.9.2.7-3.0.1.el5]
- Added xulrunner-oracle-default-prefs.js and removed the corresponding
  RedHat one.

[1.9.2.7-3]
- Include fix for 575836</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:18.351-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:29.798-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.321-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:09:25.177-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:09:25.177-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="firefox is earlier than 0:3.6.7-3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134904"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.7-3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134455"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.7-3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28137" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1386 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1386.html" ref_id="ELSA-2011-1386"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4067" ref_id="CVE-2009-4067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160" ref_id="CVE-2011-1160"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1585" ref_id="CVE-2011-1585"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1833" ref_id="CVE-2011-1833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2484" ref_id="CVE-2011-2484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2496" ref_id="CVE-2011-2496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2695" ref_id="CVE-2011-2695"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2699" ref_id="CVE-2011-2699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2723" ref_id="CVE-2011-2723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2942" ref_id="CVE-2011-2942"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3131" ref_id="CVE-2011-3131"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3188" ref_id="CVE-2011-3188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3191" ref_id="CVE-2011-3191"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3209" ref_id="CVE-2011-3209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3347" ref_id="CVE-2011-3347"/>
        <description>kernel:
[2.6.18-274.7.1.0.1.el5]

- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)

- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)

- [scsi] add additional scsi medium error handling (John Sobecki) [orabug 12904887]

- [x86] Fix lvt0 reset when hvm boot up with noapic param

- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)

  [orabug 12342275]

- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]

- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]

- bonding: reread information about speed and duplex when interface goes up (John Haxby) [orabug 11890822]

- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]

- [scsi] fix scsi hotplug and rescan race [orabug 10260172]

- fix filp_close() race (Joe Jin) [orabug 10335998]

- make xenkbd.abs_pointer=1 by default [orabug 67188919]

- [xen] check to see if hypervisor supports memory reservation change

  (Chuck Anderson) [orabug 7556514]

- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)

  [orabug 10315433]

- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]

- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]

- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]

- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]

  RDS: Fix BUG_ONs to not fire when in a tasklet

  ipoib: Fix lockup of the tx queue

  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)

  RDS: Properly unmap when getting a remote access error (Tina Yang)

  RDS: Fix locking in rds_send_drop_to()

- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)

  [orabug 9107465]

- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)

  [orabug 9764220]

- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]

- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,

  Guru Anbalagane) [orabug 6124033]

- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]

- [ib] fix memory corruption (Andy Grover) [orabug 9972346]

- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]

- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:32.075-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:29.195-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.064-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:03:56.084-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:03:56.084-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133255"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.7.1.0.1.el5-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:133187"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.7.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133197"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133101"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132855"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133092"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132976"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132779"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132763"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133306"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133362"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.7.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132641"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.7.1.0.1.el5PAE-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132410"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.7.1.0.1.el5debug-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132769"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.7.1.0.1.el5xen-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132995"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.7.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133366"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.7.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133315"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.7.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133237"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28133" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0303 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0303.html" ref_id="ELSA-2011-0303"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4249" ref_id="CVE-2010-4249"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4251" ref_id="CVE-2010-4251"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4655" ref_id="CVE-2010-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4805" ref_id="CVE-2010-4805"/>
        <description>[2.6.18-238.5.1.0.1.el5]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- fix missing aio_complete() in end_io (Joel Becker) [orabug 10365195]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [nfs] too many getattr and access calls after direct I/O [orabug 9348191]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:04.336-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:28.741-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.841-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:00:50.718-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:00:50.718-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134202"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.5.1.0.1.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133539"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.5.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134108"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133968"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134065"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134027"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133273"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134232"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134017"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133491"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134130"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.5.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134235"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.5.1.0.1.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134249"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.5.1.0.1.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:134111"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.5.1.0.1.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133457"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.5.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133818"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.5.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133805"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.5.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28132" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1132 -- dbus security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1132.html" ref_id="ELSA-2011-1132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2200" ref_id="CVE-2011-2200"/>
        <description>[1:1.2.24-5]
- Merge changes from RHEL-6 branch:
  * Drop default patch fuzz
  * Merge CVE-2010-4352.patch from RHEL-6_0-Z
- Apply patches for CVE-2011-2200
- Resolves: #725313</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:37.338-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:28.465-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.724-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:30:13.244-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:30:13.244-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133462"/>
            <criterion comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133240"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133299"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133433"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133587"/>
            <criterion comment="dbus-devel is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:132630"/>
            <criterion comment="dbus-doc is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133123"/>
            <criterion comment="dbus-libs is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133045"/>
            <criterion comment="dbus-x11 is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133574"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28127" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1154 -- libXfont security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1154.html" ref_id="ELSA-2011-1154"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2895" ref_id="CVE-2011-2895"/>
        <description>[1.4.1-2]
- cve-2011-2895.patch: LZW decompression heap corruption</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:43.948-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:27.661-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.312-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:58:01.416-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:58:01.416-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:133367"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:133247"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:133493"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:133416"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28125" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1423 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1423.html" ref_id="ELSA-2011-1423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0708" ref_id="CVE-2011-0708"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1148" ref_id="CVE-2011-1148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1466" ref_id="CVE-2011-1466"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1468" ref_id="CVE-2011-1468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1469" ref_id="CVE-2011-1469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1471" ref_id="CVE-2011-1471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1938" ref_id="CVE-2011-1938"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2202" ref_id="CVE-2011-2202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2483" ref_id="CVE-2011-2483"/>
        <description>[5.3.3-3.3]
- improve CVE-2011-1466 fix to cover CAL_GREGORIAN, CAL_JEWISH

[5.3.3-3.1]
- add security fixes for CVE-2011-2483, CVE-2011-0708, CVE-2011-1148,
  CVE-2011-1466, CVE-2011-1468, CVE-2011-1469, CVE-2011-1470,
  CVE-2011-1471, CVE-2011-1938, and CVE-2011-2202 (#740731)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:09.898-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:26.939-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.014-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:50:08.418-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:50:08.418-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133213"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133369"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133178"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133194"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133351"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133210"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132902"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133290"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133244"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133009"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133294"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133138"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132484"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133329"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133234"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133242"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133309"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133198"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132607"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133168"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132577"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133280"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133297"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133216"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133328"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133321"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133223"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133082"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133218"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132871"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133231"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133096"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133119"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132393"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133348"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132933"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133307"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133161"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133122"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133005"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133327"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133159"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133298"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132796"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133135"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133002"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132957"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28124" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0909 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0909.html" ref_id="ELSA-2011-0909"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4492" ref_id="CVE-2009-4492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0541" ref_id="CVE-2010-0541"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0188" ref_id="CVE-2011-0188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1004" ref_id="CVE-2011-1004"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1005" ref_id="CVE-2011-1005"/>
        <description>[1.8.5-19.el5_6.1]
- Address CVE-2011-1004 'Symlink race condition by removing directory trees in
  fileutils module'
  * ruby-1.8.7-CVE-2011-1004.patch
- Address CVE-2011-1005 'Untrusted codes able to modify arbitrary strings'
  * ruby-1.8.7-CVE-2011-1005.patch
- Address CVE-2011-0188 'memory corruption in BigDecimal on 64bit platforms'
  * ruby-1.8.7-CVE-2011-0188.patch
- Address CVE-CVE-2010-0541 'Ruby WEBrick javascript injection flaw'
  * ruby-1.8.7-CVE-2010-0541.patch
- Address CVE-CVE-2009-4492 'ruby WEBrick log escape sequence'
  * ruby-1.8.6-CVE-2009-4492.patch
- Resolves: rhbz#709957</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:40.196-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:26.668-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:32.871-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:36:33.067-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:36:33.067-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133729"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133540"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133531"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133494"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133382"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:132782"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133571"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133470"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:133580"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28123" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0436 -- avahi security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0436.html" ref_id="ELSA-2011-0436"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1002" ref_id="CVE-2011-1002"/>
        <description>[0.6.16-10]
- Fix for CVE-2011-1002
- Resolves: #684884</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:55.172-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:26.547-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:32.793-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:47:47.188-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:47:47.188-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="avahi is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133724"/>
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133769"/>
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133846"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:134036"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133626"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133987"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:134129"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:134131"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133832"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133998"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:133988"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28121" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0458 -- perl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0458.html" ref_id="ELSA-2010-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1168" ref_id="CVE-2010-1168"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1447" ref_id="CVE-2010-1447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5302" ref_id="CVE-2008-5302"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5303" ref_id="CVE-2008-5303"/>
        <description>[4:5.8.8-32.el5.1]
- third version of patch fix change of behaviour of rmtree for common user
- Resolves: rhbz#597203

[4:5.8.8-32.el5]
- rhbz#595416 change documentation of File::Path
- Related: rhbz#591167

[4:5.8.8-31.el5]
- remove previous fix
- Related: rhbz#591167

[4:5.8.8-30.el5]
- change config to file on Util.so
- Related: rhbz#594406

[4:5.8.8-29.el5]
- CVE-2008-5302 - use latest patch without Cwd module
- 507378 because of our paths we need to overload old Util.so in case customer installed
 Scalar::Util from cpan. In this case we marked new Util.so as .rpmnew.
- Related: rhbz#591167
- Resolves: rhbz#594406

[4:5.8.8-28.el5]
- CVE-2008-5302 perl: File::Path rmtree race condition (CVE-2005-0448) 
  reintroduced after upstream rebase to 5.8.8-1
- CVE-2010-1168 perl Safe: Intended restriction bypass via object references
- CVE-2010-1447 Safe 2.26 and earlier: Intended restriction bypass via Perl 
  object references in code executed outside safe compartment
- Related: rhbz#591167</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:13.426-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:25.891-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:32.534-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:47:17.562-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:47:17.562-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="perl is earlier than 0:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:135135"/>
          <criterion comment="perl-suidperl is earlier than 0:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:134680"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28120" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0504 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0504.html" ref_id="ELSA-2010-0504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0291" ref_id="CVE-2010-0291"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0622" ref_id="CVE-2010-0622"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1087" ref_id="CVE-2010-1087"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1088" ref_id="CVE-2010-1088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1173" ref_id="CVE-2010-1173"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1187" ref_id="CVE-2010-1187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1436" ref_id="CVE-2010-1436"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1437" ref_id="CVE-2010-1437"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1641" ref_id="CVE-2010-1641"/>
        <description>[2.6.18-194.8.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) [orabug 9504524]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [mm] Enahance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)
  [orabug 9245919]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:16.943-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:25.114-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:32.214-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:39:11.537-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:39:11.537-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134464"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.8.1.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:135016"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.8.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135019"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134485"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134891"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135067"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134134"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134746"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135030"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134983"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134528"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135112"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.8.1.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134987"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.8.1.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:135026"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.8.1.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134602"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.8.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135134"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.8.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135018"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.8.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134946"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28118" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0027 -- python security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0027.html" ref_id="ELSA-2011-0027"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4134" ref_id="CVE-2009-4134"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1449" ref_id="CVE-2010-1449"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1450" ref_id="CVE-2010-1450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1634" ref_id="CVE-2010-1634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2089" ref_id="CVE-2010-2089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5983" ref_id="CVE-2008-5983"/>
        <description>[2.4.3-43]
- add missing patch 206
Related: rhbz#549372</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:48.394-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:24.415-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:31.843-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:33:33.952-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:33:33.952-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:134502"/>
          <criterion comment="python-devel is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:134660"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:134735"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:134573"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-43.el5" test_ref="oval:org.mitre.oval:tst:134080"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28117" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0004 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0004.html" ref_id="ELSA-2011-0004"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3432" ref_id="CVE-2010-3432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3442" ref_id="CVE-2010-3442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3699" ref_id="CVE-2010-3699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3858" ref_id="CVE-2010-3858"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3859" ref_id="CVE-2010-3859"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3865" ref_id="CVE-2010-3865"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3876" ref_id="CVE-2010-3876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3880" ref_id="CVE-2010-3880"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4083" ref_id="CVE-2010-4083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4157" ref_id="CVE-2010-4157"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4161" ref_id="CVE-2010-4161"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4242" ref_id="CVE-2010-4242"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4247" ref_id="CVE-2010-4247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4248" ref_id="CVE-2010-4248"/>
        <description>[2.6.18-194.32.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin)
  [orabug 9504524]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)
  [orabug 9245919]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- make xenkbd.abs_pointer=1 by default (John Haxby) [orabug 67188919]
- fix filp_close() race (Joe Jin) [orabug 10335998]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:54.698-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:23.835-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:31.564-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:04:02.603-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:04:02.603-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134118"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.32.1.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134312"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.32.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134407"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134431"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134309"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134716"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134678"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133837"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134543"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134300"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134451"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.32.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134730"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.32.1.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134060"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.32.1.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:133862"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.32.1.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134459"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.32.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134693"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.32.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134635"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.32.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28113" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0857 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0857.html" ref_id="ELSA-2011-0857"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0862" ref_id="CVE-2011-0862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0864" ref_id="CVE-2011-0864"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0865" ref_id="CVE-2011-0865"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0867" ref_id="CVE-2011-0867"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0868" ref_id="CVE-2011-0868"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0869" ref_id="CVE-2011-0869"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0871" ref_id="CVE-2011-0871"/>
        <description>[1:1.6.0.0-1.22.1.9.8.0.1.el5_6]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.22.1.9.8]
- Resolves: rhbz#668488
- Bumped to IcedTea6 1.9.8
- RH706250, S6213702, CVE-2011-0872: (so) non-blocking sockets with TCP urgent
  disabled get still selected for read ops (win)
- RH706106, S6618658, CVE-2011-0865: Vulnerability in deserialization
- RH706111, S7012520, CVE-2011-0815: Heap overflow vulnerability in
  FileDialog.show()
- RH706139, S7013519, CVE-2011-0822, CVE-2011-0862: Integer overflows in 2D
  code
- RH706153, S7013969, CVE-2011-0867: NetworkInterface.toString can reveal
  bindings
- RH706234, S7013971, CVE-2011-0869: Vulnerability in SAAJ
- RH706239, S7016340, CVE-2011-0870: Vulnerability in SAAJ
- RH706241, S7016495, CVE-2011-0868: Crash in Java 2D transforming an image
  with scale close to zero
- RH706248, S7020198, CVE-2011-0871: ImageIcon creates Component with null acc
- RH706245, S7020373, CVE-2011-0864: JSR rewriting can overflow memory address
  size variables

[1:1.6.0.0-1.22.1.9.7]
- Resolves bz690289
- Import from RHEL-5_6-Z
- Updated to IcedTea6 1.9.7
- Removed all plugin/webstart related commented lines
- Modified bz entry format in previous logs to get around cvs ack checking bug</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:24.805-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:23.458-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:31.348-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:18:18.580-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:18:18.580-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.22.1.9.8.0.1.el5_6" test_ref="oval:org.mitre.oval:tst:133561"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.22.1.9.8.0.1.el5_6" test_ref="oval:org.mitre.oval:tst:133543"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.22.1.9.8.0.1.el5_6" test_ref="oval:org.mitre.oval:tst:133689"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.22.1.9.8.0.1.el5_6" test_ref="oval:org.mitre.oval:tst:133662"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.22.1.9.8.0.1.el5_6" test_ref="oval:org.mitre.oval:tst:133374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28112" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1919 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1919.html" ref_id="ELSA-2014-1919"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1587" ref_id="CVE-2014-1587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1590" ref_id="CVE-2014-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1592" ref_id="CVE-2014-1592"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1593" ref_id="CVE-2014-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1594" ref_id="CVE-2014-1594"/>
        <description>[31.3.0-4.0.1]
- Add firefox-oracle-default-prefs.js and firefox-oracle-default-bookmarks.html
  and remove the corresponding Red Hat ones

[31.3.0-4]
- Update to 31.3.0 ESR Build 2
- Fix for geolocation API (rhbz#1063739)

[31.2.0-5]
- splice workaround (rhbz#1150082)

[31.2.0-4]
- ppc build fix (rhbz#1151959)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:28.953-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:22.281-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:25.022-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:31.3.0-4.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:135924"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135776"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135255"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28107" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0999 -- rsync security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>rsync</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0999.html" ref_id="ELSA-2011-0999"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6200" ref_id="CVE-2007-6200"/>
        <description>[3.0.6-4]
- fix #700450 - free parsed hostnames
- fix #575022 - set TZ variable after chroot

[3.0.6-3]
- Add upstream patch to fix CVE-2011-1097 - Incremental file-list
  corruption due to temporary file_extra_cnt increments
  Resolves: #688923

[3.0.6-2]
- Remove BuildRequires dependency on popt-devel, until the package
  is being shipped with RHEL-5 (resolve build issues)

[3.0.6-1]
- Rebase to upstream version 3.0.6
  Resolves: #339971, #471182, #575022, #616093
- Make '-d, --dirs options' behaviour backward-compatible with 2.6.8
  Resolves: #339971 (comment #5)
- Truncate a copied sparse file at the end of transaction (-S, --sparse option)
  Resolves: #530866
- Add -fno-strict-aliasing to CFLAGS
- Remove obsolete rsync-2.6.8-xattr_bug.patch
- Switch license to GPLv3+ (upstream change beginning with 3.0.0)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:26.534-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:22.713-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.923-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:19:27.950-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:19:27.950-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="rsync is earlier than 0:3.0.6-4.el5" test_ref="oval:org.mitre.oval:tst:133502"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28105" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0376 -- dbus security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0376.html" ref_id="ELSA-2011-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4352" ref_id="CVE-2010-4352"/>
        <description>[1:1.2.24-4]
- Apply patch for CVE-2010-4352
- Resolves: #684852</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:05.118-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:22.509-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.808-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:51:42.856-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:51:42.856-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:134112"/>
            <criterion comment="dbus-devel is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:134116"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:133226"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:133522"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:134206"/>
            <criterion comment="dbus-devel is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:134193"/>
            <criterion comment="dbus-doc is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:133828"/>
            <criterion comment="dbus-libs is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:133813"/>
            <criterion comment="dbus-x11 is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:133703"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28104" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1380 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1380.html" ref_id="ELSA-2011-1380"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389" ref_id="CVE-2011-3389"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3521" ref_id="CVE-2011-3521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544" ref_id="CVE-2011-3544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3547" ref_id="CVE-2011-3547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3548" ref_id="CVE-2011-3548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3551" ref_id="CVE-2011-3551"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3552" ref_id="CVE-2011-3552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3553" ref_id="CVE-2011-3553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3554" ref_id="CVE-2011-3554"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3556" ref_id="CVE-2011-3556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3557" ref_id="CVE-2011-3557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3558" ref_id="CVE-2011-3558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3560" ref_id="CVE-2011-3560"/>
        <description>[1:1.6.0.0-1.40.1.9.10]
- Resolves: rhbz#744788
- Bumped to IcedTea6 1.9.8
-removed font copying
 Security fixes
  - S7000600, CVE-2011-3547: InputStream skip() information leak
  - S7019773, CVE-2011-3548: mutable static AWTKeyStroke.ctor
  - S7023640, CVE-2011-3551: Java2D TransformHelper integer overflow
  - S7032417, CVE-2011-3552: excessive default UDP socket limit under SecurityManager
  - S7046823, CVE-2011-3544: missing SecurityManager checks in scripting engine
  - S7055902, CVE-2011-3521: IIOP deserialization code execution
  - S7057857, CVE-2011-3554: insufficient pack200 JAR files uncompress error checks
  - S7064341, CVE-2011-3389: JSSE
  - S7070134, CVE-2011-3558: Hotspot unspecified issue
  - S7077466, CVE-2011-3556: RMI DGC server remote code execution
  - S7083012, CVE-2011-3557: RMI registry privileged code execution
  - S7096936, CVE-2011-3560: missing checkSetFactory calls in HttpsURLConnection
 NetX
  - PR794: javaws does not work if a Web Start app jar has a Class-Path element in the manifest</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:14.476-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:21.395-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.360-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:53:00.007-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:53:00.007-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133283"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133353"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133088"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133275"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:132798"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:132749"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133302"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133358"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133387"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133084"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28103" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0585 -- lftp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>lftp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0585.html" ref_id="ELSA-2010-0585"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2251" ref_id="CVE-2010-2251"/>
        <description>[3.7.11-4.el5_5.3]
- Related: CVE-2010-2251 - document change of xfer:clobber default
  value in manpage, respect xfer:clobber on with xfer:auto-rename on
  (old behaviour)

[3.7.11-4.el5_5.2]
- Related: CVE-2010-2251 - describe new option xfer:auto-rename
  which could restore old behaviour in manpage

[3.7.11-4.el5_5.1]
- Resolves: CVE-2010-2251 - multiple HTTP client download filename
  vulnerability (#617870)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:17.443-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:21.234-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.239-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:36:18.634-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:36:18.634-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="lftp is earlier than 0:3.7.11-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:135041"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28099" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0898 -- kvm security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0898.html" ref_id="ELSA-2010-0898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3698" ref_id="CVE-2010-3698"/>
        <description>[kvm-83-164.0.1.el5_5.25]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch

[kvm-83-164.el5_5.25]
- Adding load_gs_index to kmod symbol greylist
- Related: bz#639886
  (CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic [rhel-5.5.z])

[kvm-83-164.el5_5.24]
- Updated kversion to 2.6.18-194.17.1.el5 to match build root
- kvm.spec: fix ./configure arguments
  (ensure spice, kvm-cap-pit and kvm-cap-device-assignment are always enabled)
- kvm-kernel-KVM-Fix-fs-gs-reload-oops-with-invalid-ldt.patch [bz#639886]
- Resolves: bz#639886
  (CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic [rhel-5.5.z])
- CVE: CVE-2010-3698</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:04.449-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:20.791-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.945-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:18:25.304-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:18:25.304-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-164.0.1.el5_5.25" test_ref="oval:org.mitre.oval:tst:134454"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.0.1.el5_5.25" test_ref="oval:org.mitre.oval:tst:134828"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.0.1.el5_5.25" test_ref="oval:org.mitre.oval:tst:134792"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.0.1.el5_5.25" test_ref="oval:org.mitre.oval:tst:134646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28096" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0442 -- mysql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0442.html" ref_id="ELSA-2010-0442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1626" ref_id="CVE-2010-1626"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1848" ref_id="CVE-2010-1848"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1850" ref_id="CVE-2010-1850"/>
        <description>[5.0.77-4.3]
- Add fixes for CVE-2010-1626, CVE-2010-1848, CVE-2010-1850</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:02.679-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:20.243-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.675-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:48:28.575-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:48:28.575-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:134545"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:134998"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:135059"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:134750"/>
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:134396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28094" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0679 -- rpm security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0679.html" ref_id="ELSA-2010-0679"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2059" ref_id="CVE-2010-2059"/>
        <description>[4.4.2.3-20.el5_5.1]
- make the sbits removal behavior consistent with all the RHELs
- add proper suffix for Z branch

[4.4.2.3-19]
- fix CVE-2010-2059, fails to drop SUID/SGID bits on package upgrade (#626707)
- fix SELinux memory leak (#627630), patch from Florian Festi</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:53.315-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:19.894-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.488-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:35:24.675-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:35:24.675-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="rpm is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:134985"/>
          <criterion comment="popt is earlier than 0:1.10.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:134415"/>
          <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:134868"/>
          <criterion comment="rpm-build is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:134052"/>
          <criterion comment="rpm-devel is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:135010"/>
          <criterion comment="rpm-libs is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:134462"/>
          <criterion comment="rpm-python is earlier than 0:4.4.2.3-20.el5_5.1" test_ref="oval:org.mitre.oval:tst:134482"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28092" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2033 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2033.html" ref_id="ELSA-2011-2033"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1162" ref_id="CVE-2011-1162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577" ref_id="CVE-2011-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2494" ref_id="CVE-2011-2494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2699" ref_id="CVE-2011-2699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3188" ref_id="CVE-2011-3188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3191" ref_id="CVE-2011-3191"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3353" ref_id="CVE-2011-3353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3593" ref_id="CVE-2011-3593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4326" ref_id="CVE-2011-4326"/>
        <description>[2.6.32-200.23.1.el6uek] - net: Remove atmclip.h to prevent break kabi check. -
          KConfig: add CONFIG_UEK5=n to ol6/config-generic [2.6.32-200.22.1.el6uek] - ipv6: make
          fragment identifications less predictable (Joe Jin) {CVE-2011-2699} - vlan: fix panic when
          handling priority tagged frames (Joe Jin) {CVE-2011-3593} - ipv6: udp: fix the wrong
          headroom check (Maxim Uvarov) {CVE-2011-4326} - b43: allocate receive buffers big enough
          for max frame len + offset (Maxim Uvarov) {CVE-2011-3359} - fuse: check size of
          FUSE_NOTIFY_INVAL_ENTRY message (Maxim Uvarov) {CVE-2011-3353} - cifs: fix possible memory
          corruption in CIFSFindNext (Maxim Uvarov) {CVE-2011-3191} - crypto: md5 - Add export
          support (Maxim Uvarov) {CVE-2011-2699} - fs/partitions/efi.c: corrupted GUID partition
          tables can cause kernel oops (Maxim Uvarov) {CVE-2011-1577} - block: use struct
          parsed_partitions *state universally in partition check code (Maxim Uvarov) - net: Compute
          protocol sequence numbers and fragment IDs using MD5. (Maxim Uvarov) {CVE-2011-3188} -
          crypto: Move md5_transform to lib/md5.c (Maxim Uvarov) {CVE-2011-3188} - perf tools: do
          not look at ./config for configuration (Maxim Uvarov) {CVE-2011-2905} - Make TASKSTATS
          require root access (Maxim Uvarov) {CVE-2011-2494} - TPM: Zero buffer after copying to
          userspace (Maxim Uvarov) {CVE-2011-1162} - TPM: Call tpm_transmit with correct size (Maxim
          Uvarov){CVE-2011-1161} - fnic: fix panic while booting in fnic(Xiaowei Hu) - Revert 'PCI
          hotplug: acpiphp: set current_state to D0 in register_slot' (Guru Anbalagane) - xen: drop
          xen_sched_clock in favour of using plain wallclock time (Jeremy Fitzhardinge)
          [2.6.32-200.21.1.el6uek] - PCI: Set device power state to PCI_D0 for device without native
          PM support (Ajaykumar Hotchandani) [orabug 13033435]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:32.900-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:19.313-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.204-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36842 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:54.713-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:45.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132841"/>
            <criterion comment="ofa-2.6.32-200.23.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:133017"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132801"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132955"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132705"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:133145"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:133048"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:133025"/>
            <criterion comment="ofa-2.6.32-200.23.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132799"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133232"/>
            <criterion comment="ofa-2.6.32-200.23.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132844"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:132931"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:132839"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133043"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133067"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:132984"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133182"/>
            <criterion comment="ofa-2.6.32-200.23.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28089" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0616 -- dbus-glib security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>NetworkManager</product>
          <product>dbus-glib</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0616.html" ref_id="ELSA-2010-0616"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1172" ref_id="CVE-2010-1172"/>
        <description>NetworkManager:

[1:0.7.0-10.el5_5.1]
- Rebuild to fix D-Bus property access (for dbus-glib CVE-2010-1172)

dbus-glib:

[0.73-10]
- Add patch to fix CVE-2010-1172
  Drop broken-xml.patch which this one now incorporates
  Resolves: #588397
    (and #585395)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:13.873-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:19.142-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.053-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:08:51.725-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:08:51.725-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="NetworkManager is earlier than 0:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:134324"/>
          <criterion comment="dbus-glib is earlier than 0:0.73-10.el5_5" test_ref="oval:org.mitre.oval:tst:134058"/>
          <criterion comment="NetworkManager-devel is earlier than 0:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:135045"/>
          <criterion comment="NetworkManager-glib is earlier than 0:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:135011"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 0:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:134869"/>
          <criterion comment="NetworkManager-gnome is earlier than 0:0.7.0-10.el5_5.1" test_ref="oval:org.mitre.oval:tst:135055"/>
          <criterion comment="dbus-glib-devel is earlier than 0:0.73-10.el5_5" test_ref="oval:org.mitre.oval:tst:134973"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28087" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0221 -- squid security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0221.html" ref_id="ELSA-2010-0221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0308" ref_id="CVE-2010-0308"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2855" ref_id="CVE-2009-2855"/>
        <description>[7:2.6.STABLE21-6]
- Resolves: #561828 - CVE-2009-2855 CVE-2010-0308 squid various flaws [rhel-5.5]

[7:2.6.STABLE21-5]
- Resolves: #538738 - improved patch

[7:2.6.STABLE21-4]
- Resolves: #521926 - squid 'stop after stop' is not LSB compliant
- Resolves: #496170 - Add arp filter option
- Resolves: #516245 - negotiate support not enabled in squid
- Resolves: #538738 - Squid accelerator mode works only if port 80 is opened
- Resolves: #470843 - Squid 'error_map' does not work when used 'Accep-Encoding: gzip'</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:15.669-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:18.912-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.937-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:05:57.655-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:05:57.655-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="squid-2.6.STABLE21 is earlier than 0:6.el5" test_ref="oval:org.mitre.oval:tst:135150"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28079" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1985 -- bind97 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1985.html" ref_id="ELSA-2014-1985"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8500" ref_id="CVE-2014-8500"/>
        <description>[32:9.7.0-21.P2.1]
- Fix CVE-2014-8500 (#1171972)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:13.225-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:14.332-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136846 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:08.761-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:136209"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:136846"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:136422"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:136983"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-21.P2.el5_11.1" test_ref="oval:org.mitre.oval:tst:137010"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28078" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1458 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1458.html" ref_id="ELSA-2011-1458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313" ref_id="CVE-2011-4313"/>
        <description>[32:9.7.3-2.3.P3]
- fix DOS against recursive servers (#754398)

[32:9.7.3-2.2.P3]
- update to 9.7.3-P3 (CVE-2011-2464)

[32:9.7.3-2.1.P1]
- update to 9.7.3-P1 (CVE-2011-1910)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:31.523-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:18.317-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.588-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:29:04.238-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:29:04.238-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132293"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133291"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133018"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132539"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133282"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133070"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133086"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133236"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:133047"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132897"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132964"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:133063"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132873"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132320"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28076" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0809 -- xulrunner security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0809.html" ref_id="ELSA-2010-0809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3765" ref_id="CVE-2010-3765"/>
        <description>[1.9.2.11-4.0.1.el5_5]
- Added xulrunner-oracle-default-prefs.js and removed the corresponding
  RedHat one.

[1.9.2.11-4.el5_5]
- Add upstream patch for CVE-2010-3765</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:41.271-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:18.144-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.485-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:11:52.067-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:11:52.067-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xulrunner is earlier than 0:1.9.2.11-4.0.1.el5_5" test_ref="oval:org.mitre.oval:tst:134844"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.11-4.0.1.el5_5" test_ref="oval:org.mitre.oval:tst:134756"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28063" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0811 -- cups security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0811.html" ref_id="ELSA-2010-0811"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2431" ref_id="CVE-2010-2431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2941" ref_id="CVE-2010-2941"/>
        <description>[1.3.7-18:.8]

- Applied patch to fix cupsd memory corruption vulnerability

  (CVE-2010-2941, STR #3648, bug #624438).

- Fix latent privilege escalation vulnerability (CVE-2010-2431,

  STR #3510, bug #605397).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:41.978-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:16.734-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:27.688-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:11:20.852-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:11:20.852-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups is earlier than 0:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:134564"/>
          <criterion comment="cups-devel is earlier than 0:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:134830"/>
          <criterion comment="cups-libs is earlier than 0:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:134862"/>
          <criterion comment="cups-lpd is earlier than 0:1.3.7-18.el5_5.8" test_ref="oval:org.mitre.oval:tst:134901"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28061" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1324 -- qt4 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>qt4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1324.html" ref_id="ELSA-2011-1324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0242" ref_id="CVE-2007-0242"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3193" ref_id="CVE-2011-3193"/>
        <description>[4.2.1-1.1]
- Resolves: #737815, qt/harfbuzz buffer overflow, CVE-2011-3193
- Resolves: #234633, UTF-8 overlong sequence decoding vulnerability, CVE-2007-0242</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:27.511-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:16.494-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:27.395-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:55:36.148-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:55:36.148-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qt4 is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133533"/>
          <criterion comment="qt4-devel is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133461"/>
          <criterion comment="qt4-doc is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133172"/>
          <criterion comment="qt4-mysql is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133245"/>
          <criterion comment="qt4-odbc is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133261"/>
          <criterion comment="qt4-postgresql is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133208"/>
          <criterion comment="qt4-sqlite is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133152"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28060" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0492 -- python security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0492.html" ref_id="ELSA-2011-0492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720" ref_id="CVE-2009-3720"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3493" ref_id="CVE-2010-3493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1015" ref_id="CVE-2011-1015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1521" ref_id="CVE-2011-1521"/>
        <description>[2.4.3-44]
- add patch adapted from upstream (patch 208) to add support for building
against system expat; add --with-system-expat to configure invocation; remove
embedded copy of expat-1.95.8 from the source tree during prep
- ensure pyexpat.so gets built by explicitly listing all C modules in the
payload in %files, rather than using dynfiles
Resolves: CVE-2009-3720
- backport three security fixes to 2.4 (patches 209, 210, 211):
Resolves: CVE-2011-1521
Resolves: CVE-2011-1015
Resolves: CVE-2010-3493</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:05.371-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:16.243-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:27.256-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:04:43.800-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:04:43.800-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:133621"/>
          <criterion comment="python-devel is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:133554"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:134082"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:133788"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:134061"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28059" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1005 -- sysstat security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sysstat</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1005.html" ref_id="ELSA-2011-1005"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3852" ref_id="CVE-2007-3852"/>
        <description>[7.0.2-11]
- Related: #716959                                                                                                                                                                                             
  fix cve-2007-3852 - sysstat insecure temporary file usage

[7.0.2-10]
- Resolves: #716959
  fix cve-2007-3852 - sysstat insecure temporary file usage

[7.0.2-9]
- Related: #622557
  sar interrupt count goes backward

[7.0.2-8]
- Resolves: #694767
  iostat doesn't report statistics for shares with long names
- Related: #703095
  iostat -n - values in output overflows - problem with long device names on
  i386

[7.0.2-7]
- Resolves: #706095
  iostat -n - values in output overflows

[7.0.2-6]
- Resolves: #696672
  cifsstat resource leak

[7.0.2-5]
- Resolves: #604637
  extraneous newline in iostat report for long device names
- Resolves: #630559
  'sar -P ALL -f xxxx' does not display activity information
- Resolves: #591530
  add cifsiostat tool
- Resolves: #598794
  Enable parametrization of sadc arguments
- Resolves: #675058
  iostat: bogus value appears when device is unmounted/mounted
- Resolves: #622557
  sar interrupt count goes backward

[7.0.2-4]
- Resolves: #454617
  Though function write() executed sucessful, sadc end with an error
- Resolves: #468340
  The output of sar -I ALL/XALL is wrong in ia64 machine of RHEL5
- Resolves: #517490
  The 'sar -d ' command outputs invalid data
- Resolves: #578929
  March sar data was appended to February data
- Resolves: #579409
  The sysstat's programs such as mpstat shows one extra cpu
- Resolves: #484439
  iostat -n enhancement not report NFS client stats correctly</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:36.527-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:16.019-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:27.126-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:28:07.174-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:28:07.174-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sysstat is earlier than 0:7.0.2-11.el5" test_ref="oval:org.mitre.oval:tst:133434"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28054" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0214 -- java-1.6.0-openjdk security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0214.html" ref_id="ELSA-2011-0214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476" ref_id="CVE-2010-4476"/>
        <description>[1.6.0.0-1.36.b17]

- removed plugin. How it comes in?!

- Resolves: rhbz#676295



[1.6.0.0-1.33.b17]

- bumped release number, it was accidentaly reduced, and now lower version then last one was released.

- Resolves: rhbz#676295



[1.6.0.0-1.22.b17]

- Updated to 1.7.9 tarball

- removed patch6, fixed upstrream

- Resolves: rhbz#676295</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:44.385-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:15.647-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.824-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:30:29.394-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:30:29.394-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:133898"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134051"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134180"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:133486"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134086"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134273"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134257"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133922"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134233"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133839"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28053" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0704 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0704.html" ref_id="ELSA-2010-0704"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3081" ref_id="CVE-2010-3081"/>
        <description>[2.6.18-194.11.4.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) [orabug 9504524]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)
  [orabug 9245919]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson) 
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson) 
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro, 
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]

[2.6.18-194.11.4.el5]
- [misc] make compat_alloc_user_space() incorporate the access_ok() (Don Howard) [634463 634464] {CVE-2010-3081}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:04.169-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:15.472-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.726-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:30:48.152-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:30:48.152-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134449"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.4.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134976"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.4.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134968"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134737"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134019"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134648"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134654"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134165"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134966"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134939"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134329"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.4.0.1.el5" test_ref="oval:org.mitre.oval:tst:134818"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.4.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134961"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.4.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:135000"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.4.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134530"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.4.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134935"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.4.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134531"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.4.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134932"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28052" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0178 -- Oracle Enterprise Linux 5.5 kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0178.html" ref_id="ELSA-2010-0178"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4027" ref_id="CVE-2009-4027"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4307" ref_id="CVE-2009-4307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0727" ref_id="CVE-2010-0727"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1188" ref_id="CVE-2010-1188"/>
        <description>This update fixes the following security issues:

* a race condition was found in the mac80211 implementation, a framework
used for writing drivers for wireless devices. An attacker could trigger
this flaw by sending a Delete Block ACK (DELBA) packet to a target system,
resulting in a remote denial of service. Note: This issue only affected
users on 802.11n networks, and that also use the iwlagn driver with Intel
wireless hardware. (CVE-2009-4027, Important)

* a flaw was found in the gfs2_lock() implementation. The GFS2 locking code
could skip the lock operation for files that have the S_ISGID bit
(set-group-ID on execution) in their mode set. A local, unprivileged user
on a system that has a GFS2 file system mounted could use this flaw to
cause a kernel panic. (CVE-2010-0727, Moderate)

* a divide-by-zero flaw was found in the ext4 file system code. A local
attacker could use this flaw to cause a denial of service by mounting a
specially-crafted ext4 file system. (CVE-2009-4307, Low)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:07.527-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:15.132-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.498-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:37:43.762-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:37:43.762-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:134927"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.el5-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:134995"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134852"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:134486"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:134897"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:134771"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:135223"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:135052"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:135017"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:134942"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:135105"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:135022"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.el5PAE-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135205"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.el5debug-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:134991"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.el5xen-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135171"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135241"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134317"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28050" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1885 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1885.html" ref_id="ELSA-2014-1885"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3660" ref_id="CVE-2014-3660"/>
        <description>[2.6.26-2.1.25.0.1.el5_11]
- Add libxml2-enterprise.patch
- Replaced doc/redhat.gif in tarball with updated image

[2.6.26-2.1.25.el5]
- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1161841)

[2.6.26-2.1.24.el5]
- fixed one regexp bug and added a (rhbz#922450)
- Another small change on the algorithm for the elimination of epsilon (rhbz#922450)

[2.6.26-2.1.23.el5]
- detect and stop excessive entities expansion upon replacement (rhbz#912573)

[2.6.26-2.1.22.el5]
- fix validation issues with some XSD (rhbz#877348)
- xmlDOMWrapCloneNode discards namespace of the node parameter (rhbz#884707)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:27.631-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:20.947-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:23.661-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.25.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:135349"/>
          <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.25.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:135973"/>
          <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.25.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:135997"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28048" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0627 -- kvm security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0627.html" ref_id="ELSA-2010-0627"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0431" ref_id="CVE-2010-0431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0435" ref_id="CVE-2010-0435"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2784" ref_id="CVE-2010-2784"/>
        <description>[kvm-83-164.0.1.el5_5.21]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch

[kvm-83-164.el5_5.21]
- kvm-Fix-segfault-in-mmio-subpage-handling-code.patch [bz#619412]
- Resolves: bz#619412
  (CVE-2010-2784 qemu: insufficient constraints checking in exec.c:subpage_register() [rhel-5.5.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:08.905-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:14.430-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.158-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:09:17.911-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:09:17.911-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-164.0.1.el5_5.21" test_ref="oval:org.mitre.oval:tst:134791"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.0.1.el5_5.21" test_ref="oval:org.mitre.oval:tst:134994"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.0.1.el5_5.21" test_ref="oval:org.mitre.oval:tst:135050"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.0.1.el5_5.21" test_ref="oval:org.mitre.oval:tst:135031"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28041" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0291 -- gfs-kmod security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gfs-kmod</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0291.html" ref_id="ELSA-2010-0291"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0727" ref_id="CVE-2010-0727"/>
        <description>[0.1.34-12]
- Fixes a problem where improper locking commands can crash the system.
- Resolves: rhbz#571298

[0.1.34-11]
- Fixes 'Resource tempory unavailable' for EWOULDBLOCK message with
  flocks on gfs file
- Resolves: rhbz#515717

[0.1.34-10]
- Fixes 'Resource tempory unavailable' for EWOULDBLOCK message with 
  flocks on gfs file
- Resolves: rhbz#515717

[0.1.34-9]
- Change gfs freeze/unfreeze to use new standard
- Resolves: rhbz#487610

[0.1.34-8]
- Fixes problem that produces this error message: fatal: assertion
  'gfs_glock_is_locked_by_me(gl) &amp;&amp; gfs_glock_is_held_excl(gl)' failed
- Resolves: rhbz#471258

[0.1.34-7]
- GFS kernel panic, suid + nfsd with posix ACLs enabled
- Resolves: rhbz#513885

[0.1.34-5]
- GFS: New mount option: -o errors=withdraw|panic
- Resolves: rhbz#517145</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:51.350-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:13.631-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.731-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:14:57.830-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:14:57.830-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gfs-kmod is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:134938"/>
          <criterion comment="kmod-gfs is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:135012"/>
          <criterion comment="kmod-gfs-PAE is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:135268"/>
          <criterion comment="kmod-gfs-xen is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:135092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28040" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1019 -- libvirt security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1019.html" ref_id="ELSA-2011-1019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2511" ref_id="CVE-2011-2511"/>
        <description>[0.8.2-22.0.1.el5]
- Replaced docs/et.png in tarball

[libvirt-0.8.2-22.el5]
- Fix auditing of disk hotunplug operations (rhbz#710151)

[libvirt-0.8.2-21.el5]
- remote: Protect against integer overflow (rhbz#717207)

[0.8.2-20.el5]
- Support enabling or disabling the HPET for Xen domains (rhbz#703193)
- SMBIOS support (rhbz#661365)

[0.8.2-19.el5]
- xen: Plug memory leak in multiple serial ports support (rhbz#670789)
- Manually kill gzip if restore fails before starting qemu (rhbz#681623)
- qemu: Avoid double close on domain restore (rhbz#681623)
- virterror: Avoid API breakage with vmware (rhbz#665075)
- nwfilter: Resolve deadlock between VM ops and filter update (rhbz#697749)

[0.8.2-18.el5]
- xen: Prevent updating device when attaching a device (rhbz#662908)
- Add PCI sysfs reset access (rhbz#689880)
- xencapstest: Don't fail when Xen is installed (rhbz#690459)
- Make error reporting in libvirtd thread safe (rhbz#690733)

[0.8.2-17.el5]
- Fix event-handling data race (rhbz#671569)
- Add support for multiple serial ports into the Xen driver (rhbz#670789)
- Add missing checks for read only connections (CVE-2011-1146)
- Guess rhel macro based on dist macro (rhbz#665325)

[0.8.2-16.el5]
- Fix possible crash in virExec (rhbz#665549)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:40.958-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:13.535-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.656-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:59:17.926-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:59:17.926-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.8.2-22.0.1.el5" test_ref="oval:org.mitre.oval:tst:133579"/>
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-22.0.1.el5" test_ref="oval:org.mitre.oval:tst:133380"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.2-22.0.1.el5" test_ref="oval:org.mitre.oval:tst:133490"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28036" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1104 -- libpng security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1104.html" ref_id="ELSA-2011-1104"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2690" ref_id="CVE-2011-2690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2692" ref_id="CVE-2011-2692"/>
        <description>[2:1.2.10-7.1.el5_7.5]
- Install the correct fix for CVE-2011-2690
Resolves: #721303

[2:1.2.10-7.1.el5_7.4]
- Back-port fixes for CVE-2011-2690, CVE-2011-2692
  Note: CVE-2011-2691, announced at the same time, does not apply to 1.2.10;
  likewise for CVE-2011-2501
Resolves: #721303</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:34.835-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:13.305-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.454-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:50:29.371-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:50:29.371-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libpng is earlier than 0:1.2.10-7.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133301"/>
          <criterion comment="libpng-devel is earlier than 0:1.2.10-7.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132945"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28031" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0129 -- cups security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0129.html" ref_id="ELSA-2010-0129"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0302" ref_id="CVE-2010-0302"/>
        <description>[1:1.3.7-11:.6]
- Applied patch for CVE-2010-0302 (incomplete fix for CVE-2009-3553,
  bug #557775).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:14.238-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:12.484-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.024-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:58:08.110-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:58:08.110-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups is earlier than 0:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:135154"/>
          <criterion comment="cups-devel is earlier than 0:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:135235"/>
          <criterion comment="cups-libs is earlier than 0:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:135146"/>
          <criterion comment="cups-lpd is earlier than 0:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:135056"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28028" version="5" class="patch">
      <metadata>
        <title>ELSA-2010-2010 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-2010.html" ref_id="ELSA-2010-2010"/>
        <description>[2.6.18-194.17.1.0.2.el5] - [rds] fix access issue with rds (Chris Mason)
          {CVE-2010-3904} [orabug 10226701]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:50.467-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:12.151-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:24.823-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:134184 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:55.012-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:44.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134854"/>
          <criterion comment="ocfs2-2.6.18-194.17.1.0.2.el5 is earlier than 0:1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134731"/>
          <criterion comment="oracleasm-2.6.18-194.17.1.0.2.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134776"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134340"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134794"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134359"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134503"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134753"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:133960"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134772"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134917"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.1.0.2.el5" test_ref="oval:org.mitre.oval:tst:134820"/>
          <criterion comment="ocfs2-2.6.18-194.17.1.0.2.el5PAE is earlier than 0:1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134552"/>
          <criterion comment="ocfs2-2.6.18-194.17.1.0.2.el5debug is earlier than 0:1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134842"/>
          <criterion comment="ocfs2-2.6.18-194.17.1.0.2.el5xen is earlier than 0:1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134184"/>
          <criterion comment="oracleasm-2.6.18-194.17.1.0.2.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134615"/>
          <criterion comment="oracleasm-2.6.18-194.17.1.0.2.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134599"/>
          <criterion comment="oracleasm-2.6.18-194.17.1.0.2.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28013" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0433 -- xorg-x11-server-utils security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0433.html" ref_id="ELSA-2011-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0465" ref_id="CVE-2011-0465"/>
        <description>[7.4-15.el6_0.1]
- cve-2011-0465: Sanitize cpp macro expansion. (CVE 2011-0465)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:01.728-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:07.663-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:23.096-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:22:26.149-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:22:26.149-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.1-5.el5_6.1" test_ref="oval:org.mitre.oval:tst:133141"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1" test_ref="oval:org.mitre.oval:tst:133795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28012" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0343 -- krb5 security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0343.html" ref_id="ELSA-2010-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0629" ref_id="CVE-2010-0629"/>
        <description>[1.6.1-36.el5_5.3]
- add upstream patch to fix a few use-after-free bugs, including one in
  kadmind (CVE-2010-0629, #578185)

[1.6.1-36.el5_5.2]
- pull changes to libkrb5 to properly handle and chase off-path referrals
  back from 1.7 (#574387)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:07.951-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:07.501-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:23.002-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:41:33.257-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:41:33.257-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:134928"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:134729"/>
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:134827"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:134863"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:134388"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28008" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0062 -- bind security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0062.html" ref_id="ELSA-2010-0062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097" ref_id="CVE-2010-0097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290" ref_id="CVE-2010-0290"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0382" ref_id="CVE-2010-0382"/>
        <description>[30:9.3.6-4.P1.2]
- NSEC validation code could cause wrong NXDOMAIN responses (#554851,
  CVE-2010-0097)
- improve fix for CVE-2009-4022 (#538744)
  - {C,D}NAMEs could be returned to clients without proper DNSSEC validation
  - don't validate + cache out-of-bailiwick data returned with a secure answer.
    Refetch it instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:05.424-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:06.258-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:22.387-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:48:43.995-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:48:43.995-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:134690"/>
          <criterion comment="bind-chroot is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:135312"/>
          <criterion comment="bind-devel is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:135128"/>
          <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:135206"/>
          <criterion comment="bind-libs is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:134522"/>
          <criterion comment="bind-sdb is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:135148"/>
          <criterion comment="bind-utils is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:134940"/>
          <criterion comment="caching-nameserver is earlier than 0:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:134936"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28005" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2014 -- Oracle Linux 6 Unbreakable Enterprise kernel security fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2014.html" ref_id="ELSA-2011-2014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4346" ref_id="CVE-2010-4346"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4648" ref_id="CVE-2010-4648"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4655" ref_id="CVE-2010-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4656" ref_id="CVE-2010-4656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0521" ref_id="CVE-2011-0521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0695" ref_id="CVE-2011-0695"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1010" ref_id="CVE-2011-1010"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1090" ref_id="CVE-2011-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1478" ref_id="CVE-2011-1478"/>
        <description>[2.6.32-100.28.11.el6] - fs/partitions: Validate map_count in Mac partition
          tables {CVE-2011-1010} - nfs4: Ensure that ACL pages sent over NFS were not allocated from
          the slab (v3) {CVE-2011-1090} [2.6.32-100.28.10.el6] - Use cciss for some Smart Array
          controller for OL5 [orabug 11899706] - CVEs from RHSA-2011-0421 - install_special_mapping
          skips security_file_mmap check {CVE-2010-4346} - orinoco: fix TKIP countermeasure
          behaviour {CVE-2010-4648} - net: clear heap allocation for ethtool_get_regs()
          {CVE-2010-4655} - usb: iowarrior: don't trust report_size for buffer size {CVE-2010-4656}
          - [media] [v3,media] av7110: check for negative array offset {CVE-2011-0521} - RDMA/cma:
          Fix crash in request handlers {CVE-2011-0695} - IB/cm: Bump reference count on cm_id
          before invoking callback {CVE-2011-0695} - gro: reset skb_iif on reuse
          {CVE-2011-1478}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:53.624-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:06.027-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:22.186-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36939 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:55.560-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:43.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel-uek is earlier than 0:2.6.32-100.28.11.el5" test_ref="oval:org.mitre.oval:tst:134097"/>
          <criterion comment="ofa-2.6.32-100.28.11.el5 is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:134031"/>
          <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.28.11.el5" test_ref="oval:org.mitre.oval:tst:134045"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.28.11.el5" test_ref="oval:org.mitre.oval:tst:133633"/>
          <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.28.11.el5" test_ref="oval:org.mitre.oval:tst:134064"/>
          <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.28.11.el5" test_ref="oval:org.mitre.oval:tst:133918"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.28.11.el5" test_ref="oval:org.mitre.oval:tst:133969"/>
          <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.28.11.el5" test_ref="oval:org.mitre.oval:tst:133139"/>
          <criterion comment="ofa-2.6.32-100.28.11.el5debug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:134003"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28004" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2015 -- Oracle Linux 6 Unbreakable Enterprise kernel security fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2015.html" ref_id="ELSA-2011-2015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4565" ref_id="CVE-2010-4565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4649" ref_id="CVE-2010-4649"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0006" ref_id="CVE-2011-0006"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711" ref_id="CVE-2011-0711"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0712" ref_id="CVE-2011-0712"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726" ref_id="CVE-2011-0726"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1013" ref_id="CVE-2011-1013"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1016" ref_id="CVE-2011-1016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1019" ref_id="CVE-2011-1019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1044" ref_id="CVE-2011-1044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079" ref_id="CVE-2011-1079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080" ref_id="CVE-2011-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1093" ref_id="CVE-2011-1093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1573" ref_id="CVE-2011-1573"/>
        <description>[2.6.32-100.28.15.el6] - sctp: fix to calc the INIT/INIT-ACK chunk length
          correctly is set {CVE-2011-1573} - dccp: fix oops on Reset after close {CVE-2011-1093} -
          bridge: netfilter: fix information leak {CVE-2011-1080} - Bluetooth: bnep: fix buffer
          overflow {CVE-2011-1079} - net: don't allow CAP_NET_ADMIN to load non-netdev kernel
          modules {CVE-2011-1019} - ipip: add module alias for tunl0 tunnel device - gre: add module
          alias for gre0 tunnel device - drm/radeon/kms: check AA resolve registers on r300
          {CVE-2011-1016} - drm/radeon: fix regression with AA resolve checking {CVE-2011-1016} -
          drm: fix unsigned vs signed comparison issue in modeset ctl ioctl {CVE-2011-1013} - proc:
          protect mm start_code/end_code in /proc/pid/stat {CVE-2011-0726} - ALSA: caiaq - Fix
          possible string-buffer overflow {CVE-2011-0712} - xfs: zero proper structure size for
          geometry calls {CVE-2011-0711} - xfs: prevent leaking uninitialized stack memory in
          FSGEOMETRY_V1 {CVE-2011-0711} - ima: fix add LSM rule bug {CVE-2011-0006} - IB/uverbs:
          Handle large number of entries in poll CQ {CVE-2010-4649, CVE-2011-1044} - CAN: Use inode
          instead of kernel address for /proc file {CVE-2010-4565} [2.6.32-100.28.14.el6] - IB/qib:
          fix qib compile warning. - IB/core: Allow device-specific per-port sysfs files. - dm
          crypt: add plain64 iv. - firmware: add firmware for qib. - Infiniband: Add QLogic PCIe QLE
          InfiniBand host channel adapters support.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:50.037-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:05.443-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.921-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:133951 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:53.905-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:42.067-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel-uek is earlier than 0:2.6.32-100.28.15.el5" test_ref="oval:org.mitre.oval:tst:133780"/>
          <criterion comment="ofa-2.6.32-100.28.15.el5 is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:134090"/>
          <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.28.15.el5" test_ref="oval:org.mitre.oval:tst:134046"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.28.15.el5" test_ref="oval:org.mitre.oval:tst:134055"/>
          <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.28.15.el5" test_ref="oval:org.mitre.oval:tst:134025"/>
          <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.28.15.el5" test_ref="oval:org.mitre.oval:tst:133717"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.28.15.el5" test_ref="oval:org.mitre.oval:tst:133782"/>
          <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.28.15.el5" test_ref="oval:org.mitre.oval:tst:134041"/>
          <criterion comment="ofa-2.6.32-100.28.15.el5debug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133951"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28003" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0361 -- sudo security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0361.html" ref_id="ELSA-2010-0361"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1163" ref_id="CVE-2010-1163"/>
        <description>[1.7.2p1-6]
- added second patch for CVE-2010-0426 (#580441)
  Resolves: #580525</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:17.782-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:05.281-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.771-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:09:45.687-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:09:45.687-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-6.el5_5" test_ref="oval:org.mitre.oval:tst:135139"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27999" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0926 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0926.html" ref_id="ELSA-2011-0926"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2464" ref_id="CVE-2011-2464"/>
        <description>[32:9.7.3-2.2.P3]

- update to 9.7.3-P3 (CVE-2011-2464)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:18.835-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:04.475-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.473-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:20:29.658-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:20:29.658-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133598"/>
            <criterion comment="bind97-chroot is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133480"/>
            <criterion comment="bind97-devel is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133668"/>
            <criterion comment="bind97-libs is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133708"/>
            <criterion comment="bind97-utils is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133325"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133637"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133735"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133661"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133189"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133066"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:132772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27998" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0154 -- hplip security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>hplip</product>
          <product>hplip3</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0154.html" ref_id="ELSA-2011-0154"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4267" ref_id="CVE-2010-4267"/>
        <description>[3.9.8-33:.1]

- Applied patch to fix CVE-2010-4267, remote stack overflow

  vulnerability (bug #662740).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:39.736-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:04.258-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.326-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:36:05.835-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:36:05.835-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hplip is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:134219"/>
            <criterion comment="hplip3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134590"/>
            <criterion comment="hpijs is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:134122"/>
            <criterion comment="hpijs3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134457"/>
            <criterion comment="hplip3-common is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134701"/>
            <criterion comment="hplip3-gui is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134279"/>
            <criterion comment="hplip3-libs is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134467"/>
            <criterion comment="libsane-hpaio is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:134689"/>
            <criterion comment="libsane-hpaio3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134702"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hplip is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134255"/>
            <criterion comment="hpijs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134744"/>
            <criterion comment="hplip-common is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134433"/>
            <criterion comment="hplip-gui is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134584"/>
            <criterion comment="hplip-libs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134640"/>
            <criterion comment="libsane-hpaio is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134687"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27997" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0478 -- libvirt security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0478.html" ref_id="ELSA-2011-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1486" ref_id="CVE-2011-1486"/>
        <description>[0.8.2-15.0.1.el5_6.4]
- Replaced docs/et.png in tarball

[0.8.2-15.el5_6.4]
- Make error reporting in libvirtd thread safe (CVE-2011-1486)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:44.953-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:04.162-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.245-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:05:29.605-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:05:29.605-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.8.2-15.0.1.el5_6.4" test_ref="oval:org.mitre.oval:tst:134012"/>
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-15.0.1.el5_6.4" test_ref="oval:org.mitre.oval:tst:133980"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.2-15.0.1.el5_6.4" test_ref="oval:org.mitre.oval:tst:133974"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27994" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0144 -- cpio security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>cpio</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0144.html" ref_id="ELSA-2010-0144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4476" ref_id="CVE-2007-4476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0624" ref_id="CVE-2010-0624"/>
        <description>[2.6-23.1]
- CVE-2010-0624 fix heap-based buffer overflow by expanding
  a specially-crafted archive
- CVE-2007-4476 fix stack crashing in safer_name_suffix</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:09.721-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:03.799-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.067-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:34:36.178-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:34:36.178-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="cpio is earlier than 0:2.6-23.el5_4.1" test_ref="oval:org.mitre.oval:tst:135258"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27991" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0347 -- nss_db security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nss_db</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0347.html" ref_id="ELSA-2010-0347"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0826" ref_id="CVE-2010-0826"/>
        <description>[2.2-35.4]
- import Kees Cook's patch to fix accidental leakage of part of ./DB_CONFIG
  (#580542, CVE-2010-0826)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:00.197-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:03.473-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.885-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:08:39.756-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:08:39.756-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="nss_db is earlier than 0:2.2-35.4.el5_5" test_ref="oval:org.mitre.oval:tst:134727"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27990" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1959 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1959.html" ref_id="ELSA-2014-1959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0181" ref_id="CVE-2014-0181"/>
        <description>kernel [2.6.18-400] - [net] bridge: disable snooping if there is no querier
          (Frantisek Hrbata) [902454] - [s390] kernel: sysinfo: convert /proc/sysinfo to seqfile
          (Alexander Gordeev) [1131283] - [net] netlink: verify permisions of socket creator (Jiri
          Benc) [1094266] {CVE-2014-0181} - [net] netlink: store effective caps at socket() time
          (Jiri Benc) [1094266] {CVE-2014-0181} - [net] netlink: Rename netlink_capable
          netlink_allowed (Jiri Benc) [1094266] {CVE-2014-0181} - [net] netlink: Fix permission
          check in netlink_connect() (Jiri Benc) [1094266] {CVE-2014-0181} - [net] netlink: fix
          possible spoofing from non-root processes (Jiri Benc) [1094266] {CVE-2014-0181} - [net]
          netlink: Make NETLINK_USERSOCK work again (Jiri Benc) [1094266] {CVE-2014-0181} - [net]
          netlink: fix for too early rmmod (Jiri Benc) [1094266] {CVE-2014-0181} [2.6.18-399] -
          [kernel] do_setitimer: cancel real_timer if try_to_cancel fails (Oleg Nesterov)
          [1134654]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:32.482-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:18.342-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:19.794-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135728 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:53.042-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:41.877-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135684"/>
          <criterion comment="ocfs2-2.6.18-400.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135706"/>
          <criterion comment="oracleasm-2.6.18-400.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135842"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135758"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135984"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135951"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135942"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135020"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135483"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135955"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135809"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-400.el5" test_ref="oval:org.mitre.oval:tst:135130"/>
          <criterion comment="ocfs2-2.6.18-400.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135702"/>
          <criterion comment="ocfs2-2.6.18-400.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135728"/>
          <criterion comment="ocfs2-2.6.18-400.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135926"/>
          <criterion comment="oracleasm-2.6.18-400.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135872"/>
          <criterion comment="oracleasm-2.6.18-400.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135713"/>
          <criterion comment="oracleasm-2.6.18-400.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135917"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27982" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0181 -- brltty security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>brltty</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0181.html" ref_id="ELSA-2010-0181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3279" ref_id="CVE-2008-3279"/>
        <description>[3.7.2-4]
- use rpm macros more consistently
- add manual page for brltty.conf
- add more documentation
- install the default brltty-pm.conf to docdir only
- Resolves: #530554
- silence the postinstall scriptlet
- Resolves: #529163

[3.7.2-3]
- escape rpm macros in the rpm change log
- remove bogus rpath from libbrlttybba.so (CVE-2008-3279, #457942)
- add dependencies to bind the subpackages from one build together

[3.7.2-2]
- fix building with newer kernel-headers (#456247)
- do not strip debug info during install (#500545)
- Resolves: rhbz #456247 #500545</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:52.834-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:02.492-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.407-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:47:53.808-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:47:53.808-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="brltty is earlier than 0:3.7.2-4.el5" test_ref="oval:org.mitre.oval:tst:135233"/>
          <criterion comment="brlapi is earlier than 0:0.4.1-4.el5" test_ref="oval:org.mitre.oval:tst:134622"/>
          <criterion comment="brlapi-devel is earlier than 0:0.4.1-4.el5" test_ref="oval:org.mitre.oval:tst:135013"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27980" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0659 -- httpd security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0659.html" ref_id="ELSA-2010-0659"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1452" ref_id="CVE-2010-1452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2791" ref_id="CVE-2010-2791"/>
        <description>[2.2.3-43.0.1.el5_5.3 ]
- replace index.html with Oracle's index page oracle_index.html
- update vstring and distro in specfile

[2.2.3-43.3]
- mod_ssl: improved fix for SSLRequire's OID() function (#625452)

[2.2.3-43.2]
- add security fixes for CVE-2010-1452, CVE-2010-2791 (#623210)
- mod_deflate: rebase to 2.2.15 (#625435)
- stop multiple invocations of filter init functions (#625451)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:59.959-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:02.234-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.266-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:05:58.120-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:05:58.120-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd is earlier than 0:2.2.3-43.0.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134656"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-43.0.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134914"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.3-43.0.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134782"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-43.0.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:134996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27974" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3089 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3089.html" ref_id="ELSA-2014-3089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" ref_id="CVE-2014-3687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" ref_id="CVE-2014-3673"/>
        <description>kernel-uek [2.6.32-400.36.11uek] - net: sctp: fix panic on duplicate ASCONF
          chunks (Daniel Borkmann) [Orabug: 20010592] {CVE-2014-3687} - net: sctp: fix
          skb_over_panic when receiving malformed ASCONF chunks (Daniel Borkmann) [Orabug: 20010579]
          {CVE-2014-3673}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:44.746-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:51.824-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:22.217-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:134812 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:52.595-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:41.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135550"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:135609"/>
            <criterion comment="ofa-2.6.32-400.36.11.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:135618"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135374"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135487"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135522"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:134639"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135156"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135388"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:134812"/>
            <criterion comment="ofa-2.6.32-400.36.11.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:135617"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135259"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:135496"/>
            <criterion comment="ofa-2.6.32-400.36.11.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:134971"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135529"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135614"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135147"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135563"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135480"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135199"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:135375"/>
            <criterion comment="ofa-2.6.32-400.36.11.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:135192"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27973" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0749 -- poppler security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>poppler</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0749.html" ref_id="ELSA-2010-0749"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3702" ref_id="CVE-2010-3702"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3704" ref_id="CVE-2010-3704"/>
        <description>[0.5.4-4.4.el5_5.14]
- Add poppler-0.5.4-CVE-2010-3702.patch
    (Properly initialize parser)
- Add poppler-0.5.4-CVE-2010-3704.patch
    (Fix crash in broken pdf (code &lt; 0))
- Resolves: #639839</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:57.388-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:01.615-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:19.805-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:54:16.634-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:54:16.634-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_5.14" test_ref="oval:org.mitre.oval:tst:134926"/>
          <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_5.14" test_ref="oval:org.mitre.oval:tst:134769"/>
          <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_5.14" test_ref="oval:org.mitre.oval:tst:134700"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27970" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0429 -- postgresql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0429.html" ref_id="ELSA-2010-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4136" ref_id="CVE-2009-4136"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0442" ref_id="CVE-2010-0442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0733" ref_id="CVE-2010-0733"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1169" ref_id="CVE-2010-1169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1170" ref_id="CVE-2010-1170"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1975" ref_id="CVE-2010-1975"/>
        <description>[8.1.21-1.el5_5.1]
- Update to PostgreSQL 8.1.21 to fix CVE-2010-1169, CVE-2010-1170,
  CVE-2009-4136, CVE-2010-0733, CVE-2010-0442, and assorted other bugs
  described at
  http://www.postgresql.org/docs/8.1/static/release.html
Resolves: #586058</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:01.654-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:00.167-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:19.213-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:05:21.736-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:05:21.736-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135079"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134489"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134965"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134345"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135001"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135099"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134784"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134875"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:134980"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:135113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27966" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0281 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0281.html" ref_id="ELSA-2011-0281"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4448" ref_id="CVE-2010-4448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4450" ref_id="CVE-2010-4450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4465" ref_id="CVE-2010-4465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4469" ref_id="CVE-2010-4469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4470" ref_id="CVE-2010-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4472" ref_id="CVE-2010-4472"/>
        <description>[1.6.0.0-1.39.b17]
- respin of  IcedTea6 1.7.10
- Resolves: rhbz#676276

[1.6.0.0-1.37.b17]
- Updated to IcedTea6 1.7.10
- Resolves: rhbz#676276</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:43.616-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:59.277-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:18.870-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:30:06.829-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:30:06.829-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134038"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134243"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134268"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134261"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134283"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134238"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133438"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133466"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134011"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133975"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27965" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0838 -- gimp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0838.html" ref_id="ELSA-2011-0838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1570" ref_id="CVE-2009-1570"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4540" ref_id="CVE-2010-4540"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4541" ref_id="CVE-2010-4541"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4542" ref_id="CVE-2010-4542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4543" ref_id="CVE-2010-4543"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1178" ref_id="CVE-2011-1178"/>
        <description>[2:2.2.13-2.0.7.2]
- fix various overflows (#537356, #666793, #689831, #703403, #703405, #703407,
  - unfuzz gimphelpmissing, icontheme patches</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:27.740-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:58.998-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:18.733-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:50:47.637-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:50:47.637-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gimp is earlier than 0:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:133882"/>
          <criterion comment="gimp-devel is earlier than 0:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:133516"/>
          <criterion comment="gimp-libs is earlier than 0:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:133489"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27959" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2010 -- Oracle Linux 6 Unbreakable Enterprise kernel security fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2010.html" ref_id="ELSA-2011-2010"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4165" ref_id="CVE-2010-4165"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4169" ref_id="CVE-2010-4169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4249" ref_id="CVE-2010-4249"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4668" ref_id="CVE-2010-4668"/>
        <description>[2.6.32-100.28.9.el6] - sync up the version [2.6.32-100.28.8.el6] - [block]
          check for proper length of iov entries earlier in blk_rq_map_user_iov (Xiaotian Feng)
          {CVE-2010-4668} - scm: lower SCM_MAX_FD (Eric Dumazet) {CVE-2010-4249} - perf_events: Fix
          perf_counter_mmap() hook in mprotect() (Pekka Enberg) {CVE-2010-4169} - tcp: Increase
          TCP_MAXSEG socket option minimum (David S. Miller) {CVE-2010-4165} - Enable module force
          load option [orabug 11782146] - Enable vmw balloon and pvscsi (Guru Anbalagane) [orabug
          11697522] [2.6.32-100.28.7.el6] - build from git [2.6.32-100.28.6.el6] - Remove
          crashkernel option if it is present [bug 11714928]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:40.825-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:57.570-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:17.995-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:134000 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:54.484-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:41.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel-uek is earlier than 0:2.6.32-100.28.9.el5" test_ref="oval:org.mitre.oval:tst:134054"/>
          <criterion comment="ofa-2.6.32-100.28.9.el5 is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:134234"/>
          <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.28.9.el5" test_ref="oval:org.mitre.oval:tst:134146"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.28.9.el5" test_ref="oval:org.mitre.oval:tst:133679"/>
          <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.28.9.el5" test_ref="oval:org.mitre.oval:tst:133857"/>
          <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.28.9.el5" test_ref="oval:org.mitre.oval:tst:133910"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.28.9.el5" test_ref="oval:org.mitre.oval:tst:133793"/>
          <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.28.9.el5" test_ref="oval:org.mitre.oval:tst:134205"/>
          <criterion comment="ofa-2.6.32-100.28.9.el5debug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:134000"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27958" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1845 -- tomcat5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1845.html" ref_id="ELSA-2011-1845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3718" ref_id="CVE-2010-3718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0013" ref_id="CVE-2011-0013"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1184" ref_id="CVE-2011-1184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2204" ref_id="CVE-2011-2204"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5062" ref_id="CVE-2011-5062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5063" ref_id="CVE-2011-5063"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5064" ref_id="CVE-2011-5064"/>
        <description>[0:5.5.23-0jpp.22]
- Resolves: CVE-2011-0013 rhbz 675931
- Resolves: CVE-2010-3718 rhbz 675931
- Resolves: CVE-2011-1184 rhbz 744983
- Resolves: CVE-2011-2204 rhbz 719181</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:33.616-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:56.790-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:17.667-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:27:05.457-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:27:05.457-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132528"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132817"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132986"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132852"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:133042"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132311"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132642"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132952"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132987"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:132720"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.22.el5_7" test_ref="oval:org.mitre.oval:tst:133037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27956" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0580 -- tomcat5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0580.html" ref_id="ELSA-2010-0580"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2693" ref_id="CVE-2009-2693"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2696" ref_id="CVE-2009-2696"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2902" ref_id="CVE-2009-2902"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2227" ref_id="CVE-2010-2227"/>
        <description>[0:5.5.23-0jpp.9]
- Resolves: rhbz#619424 fixed servlet-api typo. serve4-api to servlet-api
- RHSA-2010:9748

[0:5.5.23-0jpp.8]
- Patches backported from RHEL-5 tomcat5-5.5.23-0jpp.10.el5
- Updated init script for LSB compliance, catalina.log permissions
- Resolves: CVE-2009-2693, CVE-2009-2902, CVE-2010-2227
- CVE_2010-0781</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:58.587-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:56.383-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:17.475-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:12:34.520-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:12:34.520-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134999"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134913"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134867"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:135042"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:135071"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:135061"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134399"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134943"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134092"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134099"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:134801"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27955" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2038 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
          <product>mlnx_en</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2038.html" ref_id="ELSA-2011-2038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576" ref_id="CVE-2011-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4127" ref_id="CVE-2011-4127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1493" ref_id="CVE-2011-1493"/>
        <description>kernel-uek [2.6.32-300.4.1.el6uek] - [pci] intel-iommu: Default to non-coherent
          for domains unattached to iommus (Joe Jin) - [dm] do not forward ioctls from logical
          volumes to the underlying device (Joe Jin) {CVE-2011-4127} - [block] fail SCSI passthrough
          ioctls on partition devices (Joe Jin) {CVE-2011-4127} - [block] add and use
          scsi_blk_cmd_ioctl (Joe Jin) {CVE-2011-4127} - [net] gro: reset vlan_tci on reuse (Dan
          Carpenter) {CVE-2011-1576} - [net] rose: Add length checks to CALL_REQUEST parsing (Ben
          Hutchings) {CVE-2011-1493} - [net] rose_loopback_timer sets VC number &lt;=
          ROSE_DEFAULT_MAXVC (Bernard Pidoux F6BVP) {CVE-2011-1493}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:29.033-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:56.156-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:17.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27955 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:51.825-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:40.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132686"/>
            <criterion comment="ofa-2.6.32-300.4.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132445"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132912"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132773"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:133073"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132183"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:133049"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132946"/>
            <criterion comment="ofa-2.6.32-300.4.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132496"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132385"/>
            <criterion comment="mlnx_en-2.6.32-300.4.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132710"/>
            <criterion comment="ofa-2.6.32-300.4.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132812"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132548"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132412"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132956"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132270"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132835"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132824"/>
            <criterion comment="mlnx_en-2.6.32-300.4.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132906"/>
            <criterion comment="ofa-2.6.32-300.4.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133015"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27954" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0321 -- automake security update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>automake</product>
          <product>automake14</product>
          <product>automake15</product>
          <product>automake16</product>
          <product>automake17</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0321.html" ref_id="ELSA-2010-0321"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4029" ref_id="CVE-2009-4029"/>
        <description>[1.9.6-2.3]
- increase delay in self checks
- add delays in aclocal7 self check
  http://osdir.com/ml/sysutils.automake.bugs/2006-09/msg00012.html
- preserve timestamps of configure files

[1.9.6-2.2]
- add fix for CVE-2009-4029</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:18.821-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:55.968-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:17.167-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:51:11.348-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:51:11.348-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="automake is earlier than 0:1.9.6-2.3.el5" test_ref="oval:org.mitre.oval:tst:134278"/>
          <criterion comment="automake14 is earlier than 0:1.4p6-13.el5.1" test_ref="oval:org.mitre.oval:tst:135271"/>
          <criterion comment="automake15 is earlier than 0:1.5-16.el5.2" test_ref="oval:org.mitre.oval:tst:135183"/>
          <criterion comment="automake16 is earlier than 0:1.6.3-8.el5.1" test_ref="oval:org.mitre.oval:tst:134906"/>
          <criterion comment="automake17 is earlier than 0:1.7.9-7.el5.2" test_ref="oval:org.mitre.oval:tst:135207"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27952" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0271 -- kvm security, bug fix and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0271.html" ref_id="ELSA-2010-0271"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0430" ref_id="CVE-2010-0430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0741" ref_id="CVE-2010-0741"/>
        <description>A flaw was found in the way QEMU-KVM handled erroneous data provided by
the Linux virtio-net driver, used by guest operating systems. Due to a
deficiency in the TSO (TCP segment offloading) implementation, a guest's
virtio-net driver would transmit improper data to a certain QEMU-KVM
process on the host, causing the guest to crash. A remote attacker could
use this flaw to send specially-crafted data to a target guest system,
causing that guest to crash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:53.040-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:55.488-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:16.893-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:18:45.956-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:18:45.956-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="kvm is earlier than 0:83-164.0.1.el5" test_ref="oval:org.mitre.oval:tst:135120"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27950" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0633 -- qspice security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>qspice</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0633.html" ref_id="ELSA-2010-0633"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0428" ref_id="CVE-2010-0428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0429" ref_id="CVE-2010-0429"/>
        <description>[0.3.0-54.el5_5.2]
- Fix unsafe accesses
  + spice: drop libpng from windows components (537849)
  + libspice: fix unsafe guest data accessing
Resolves: #568719
  + fix unsafe free() call.
Resolves: #568723
  + spice server: fix unsafe cursor items handling.
Resolves: #568719</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:56.077-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:55.062-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:16.581-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:09:57.531-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:09:57.531-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qspice is earlier than 0:0.3.0-54.el5_5.2" test_ref="oval:org.mitre.oval:tst:134788"/>
          <criterion comment="qspice-libs is earlier than 0:0.3.0-54.el5_5.2" test_ref="oval:org.mitre.oval:tst:135035"/>
          <criterion comment="qspice-libs-devel is earlier than 0:0.3.0-54.el5_5.2" test_ref="oval:org.mitre.oval:tst:134797"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27948" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0336 -- tomcat5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0336.html" ref_id="ELSA-2011-0336"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476" ref_id="CVE-2010-4476"/>
        <description>[0:5.5.23-0jpp.17]
- Resolves: rhbz 674599 JDK Double.parseDouble DoS</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:12.218-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:54.665-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:16.207-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:51:13.152-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:51:13.152-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134230"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134236"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134163"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134185"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134016"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134216"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134240"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:133709"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:134160"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:133745"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:133948"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27939" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1241 -- ecryptfs-utils security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1241.html" ref_id="ELSA-2011-1241"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1831" ref_id="CVE-2011-1831"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1832" ref_id="CVE-2011-1832"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1834" ref_id="CVE-2011-1834"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1835" ref_id="CVE-2011-1835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1837" ref_id="CVE-2011-1837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3145" ref_id="CVE-2011-3145"/>
        <description>[82-6.3]
- do not forget to set the group id in mount.ecryptfs_private

[82-6.2]
- fix regression in ecryptfs-setup-private

[82-6.1]
- security fixes:
- privilege escalation via mountpoint race conditions (CVE-2011-1831, CVE-2011-1832)
- race condition when checking source during mount (CVE-2011-1833)
- mtab corruption via improper handling (CVE-2011-1834)
- key poisoning via insecure temp directory handling (CVE-2011-1835)
- arbitrary file overwrite via lock counter race (CVE-2011-1837)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:43.558-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:53.407-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.468-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:47:19.039-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:47:19.039-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:133573"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:133220"/>
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:133195"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:133444"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:133412"/>
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:132832"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27934" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0819 -- pam security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pam</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0819.html" ref_id="ELSA-2010-0819"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3316" ref_id="CVE-2010-3316"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3435" ref_id="CVE-2010-3435"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3853" ref_id="CVE-2010-3853"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4707" ref_id="CVE-2010-4707"/>
        <description>[0.99.6.2-6.2]
- fix insecure dropping of priviledges in pam_xauth
  and pam_mail - CVE-2010-3316 (#637898), CVE-2010-3435 (#641335)
- fix insecure executing of scripts with user supplied environment
  variables in pam_namespace - CVE-2010-3853 (#643043)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:38.666-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:52.862-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.132-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:37:52.483-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:37:52.483-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pam is earlier than 0:0.99.6.2-6.el5_5.2" test_ref="oval:org.mitre.oval:tst:134734"/>
          <criterion comment="pam-devel is earlier than 0:0.99.6.2-6.el5_5.2" test_ref="oval:org.mitre.oval:tst:134382"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27933" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1401 -- xen security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1401.html" ref_id="ELSA-2011-1401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3346" ref_id="CVE-2011-3346"/>
        <description>[3.0.3-132.el5_7.2]
- Release device backends before restarting guest on the destination machine (rhbz 743850)
- Fix SCSI buffer overflow and disable SCSI CD-ROMs (rhbz 736289)

[3.0.3-132.el5_7.1]
- hotplug: set netback/tap MTU to the same value as the bridge MTU (rhbz 738608)
- copy the MTU of the physical interface to the Xen bridge (rhbz 738610)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:23.092-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:52.681-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.006-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:08:42.131-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:08:42.131-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xen is earlier than 0:3.0.3-132.el5_7.2" test_ref="oval:org.mitre.oval:tst:132757"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-132.el5_7.2" test_ref="oval:org.mitre.oval:tst:133342"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-132.el5_7.2" test_ref="oval:org.mitre.oval:tst:133376"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27931" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0652 -- ImageMagick security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0652.html" ref_id="ELSA-2010-0652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882" ref_id="CVE-2009-1882"/>
        <description>[6.2.8.0-4.el5_5.2]
- Fix SGI image decoding (625058)

[6.2.8.0-4.el5_5.1]
- Add fix for CVE-2009-1882 (504304)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:02.037-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:52.438-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.902-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:11:21.441-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:11:21.441-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:134638"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:134559"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:134759"/>
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:134747"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_5.2" test_ref="oval:org.mitre.oval:tst:134949"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27927" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0126 -- glibc security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0126.html" ref_id="ELSA-2012-0126"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0830" ref_id="CVE-2010-0830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5029" ref_id="CVE-2009-5029"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5064" ref_id="CVE-2009-5064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1089" ref_id="CVE-2011-1089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4609" ref_id="CVE-2011-4609"/>
        <description>[2.5-65.el5_7.3]
- Use correct type when casting d_tag (#767687)
- Report write error  in addmnt even for cached streams (#767687)
- ldd: Never run file directly (#767687).
- Workaround misconfigured system (#767687)

[2.5-65.el5_7.2]
- Check values from TZ file header (#767687)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:08.389-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:51.806-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.621-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:14:22.631-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:14:22.631-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:132452"/>
          <criterion comment="glibc-common is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:132508"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:132510"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:132265"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:132119"/>
          <criterion comment="nscd is earlier than 0:2.5-65.el5_7.3" test_ref="oval:org.mitre.oval:tst:132192"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27925" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0017 -- libxml2 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0017.html" ref_id="ELSA-2012-0017"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3905" ref_id="CVE-2011-3905"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3919" ref_id="CVE-2011-3919"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4008" ref_id="CVE-2010-4008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0216" ref_id="CVE-2011-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1944" ref_id="CVE-2011-1944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2834" ref_id="CVE-2011-2834"/>
        <description>[2.6.26-2.1.12.0.1.el5_7.2]
- Add libxml2-enterprise.patch
- Replaced docs/redhat.gif in tarball with updated image

[2.6.26-2.1.12.el5_7.2]
- Fix the semantic of XPath axis for namespace/attribute nodes CVE-2010-4008
- Fix an off by one error in encoding CVE-2011-0216
- Fix some potential problems on reallocation failures CVE-2011-1944
- Fix missing error status in XPath evaluation CVE-2011-2834
- Make sure the parser returns when getting a Stop order CVE-2011-3905
- Fix an allocation error when copying entities CVE-2011-3919.patch
- Resolves: rhbz#771906</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:16.857-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:51.493-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.420-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:10:15.799-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:10:15.799-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.12.0.1.el5_7.2" test_ref="oval:org.mitre.oval:tst:132845"/>
          <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.12.0.1.el5_7.2" test_ref="oval:org.mitre.oval:tst:132618"/>
          <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.12.0.1.el5_7.2" test_ref="oval:org.mitre.oval:tst:132876"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27920" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0127 -- mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0127.html" ref_id="ELSA-2012-0127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0075" ref_id="CVE-2012-0075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0087" ref_id="CVE-2012-0087"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0101" ref_id="CVE-2012-0101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0102" ref_id="CVE-2012-0102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0114" ref_id="CVE-2012-0114"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0484" ref_id="CVE-2012-0484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0490" ref_id="CVE-2012-0490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1849" ref_id="CVE-2010-1849"/>
        <description>[5.0.95-1.el5_7.1]
- Update to 5.0.95, to get the last upstream bugfixes in this release series
  including numerous CVEs announced in January 2012
Resolves: #787140</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:44:59.837-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:51.009-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.140-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:39:03.405-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:39:03.405-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132255"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132032"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132259"/>
          <criterion comment="mysql-server is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132214"/>
          <criterion comment="mysql-test is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27918" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0412 -- glibc security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0412.html" ref_id="ELSA-2011-0412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0296" ref_id="CVE-2010-0296"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0536" ref_id="CVE-2011-0536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1071" ref_id="CVE-2011-1071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1095" ref_id="CVE-2011-1095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1658" ref_id="CVE-2011-1658"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1659" ref_id="CVE-2011-1659"/>
        <description>[2.5-58.el5_6.2]
- Avoid too much stack use in fnmatch (#681054, CVE-2011-1071)
- Properly quote output of locale (#625893, CVE-2011-1095)
- Don't leave empty element in rpath when skipping the first element,
  ignore rpath elements containing non-isolated use of  when
  privileged (#667974, CVE-2011-0536)
- Fix handling of newline in addmntent (#559579, CVE-2010-0296)

[2.5-58.el5_6.1]
- Don't ignore  in libraries (#682991)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:47.447-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:50.644-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:13.925-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:25:09.642-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:25:09.642-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:133981"/>
          <criterion comment="glibc-common is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:134106"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:133484"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:134013"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:133838"/>
          <criterion comment="nscd is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:134098"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27916" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2037 -- Unbreakable Enterprise kernel security and bug fix update
          (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2037.html" ref_id="ELSA-2011-2037"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020" ref_id="CVE-2011-1020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577" ref_id="CVE-2011-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1585" ref_id="CVE-2011-1585"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2495" ref_id="CVE-2011-2495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2525" ref_id="CVE-2011-2525"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3638" ref_id="CVE-2011-3638"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4110" ref_id="CVE-2011-4110"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4330" ref_id="CVE-2011-4330"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2707" ref_id="CVE-2011-2707"/>
        <description>[2.6.32-300.3.1.el6uek] - proc: fix oops on invalid /proc/&lt;pid>/maps
          access (Linux Torvalds) - Revert 'capabilities: do not grant full privs for setuid w/ file
          caps + no effective caps' (Joe Jin) - [mm]: Use MMF_COMPAT instead ia32_compat to prevent
          kabi be broken (Joe Jin) - proc: enable writing to /proc/pid/mem (Stephen Wilson) - proc:
          make check_mem_permission() return an mm_struct on success (Stephen Wilson) - proc: hold
          cred_guard_mutex in check_mem_permission() (Joe Jin) - proc: disable mem_write after exec
          (Stephen Wilson) - mm: implement access_remote_vm (Stephen Wilson) - mm: factor out main
          logic of access_process_vm (Stephen Wilson) - mm: use mm_struct to resolve gate vma's in
          __get_user_pages (Stephen Wilson) - mm: arch: rename in_gate_area_no_task to
          in_gate_area_no_mm (Stephen Wilson) - mm: arch: make in_gate_area take an mm_struct
          instead of a task_struct (Stephen Wilson) - mm: arch: make get_gate_vma take an mm_struct
          instead of a task_struct (Stephen Wilson) - x86: mark associated mm when running a task in
          32 bit compatibility mode (Stephen Wilson) - x86: add context tag to mark mm when running
          a task in 32-bit compatibility mode (Stephen Wilson) - auxv: require the target to be
          tracable (or yourself) (Al Viro) - close race in /proc/*/environ (Al Viro) - report errors
          in /proc/*/*map* sanely (Al Viro) - pagemap: close races with suid execve (Al Viro) - make
          sessionid permissions in /proc/*/task/* match those in /proc/* (Al Viro) - Revert 'report
          errors in /proc/*/*map* sanely' (Joe Jin) - Revert 'proc: fix oops on invalid
          /proc/&lt;pid>/maps access' (Joe Jin)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:13.623-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:49.641-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:13.435-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132958 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:54.289-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:39.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132869"/>
            <criterion comment="ofa-2.6.32-300.3.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132938"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132368"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:133054"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132935"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132947"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132175"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132973"/>
            <criterion comment="ofa-2.6.32-300.3.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132756"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132929"/>
            <criterion comment="ofa-2.6.32-300.3.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132557"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132408"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132978"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:133116"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132891"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:133094"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132936"/>
            <criterion comment="ofa-2.6.32-300.3.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132958"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27914" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2003 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2003.html" ref_id="ELSA-2012-2003"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4081" ref_id="CVE-2011-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4347" ref_id="CVE-2011-4347"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0038" ref_id="CVE-2012-0038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0045" ref_id="CVE-2012-0045"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0207" ref_id="CVE-2012-0207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4077" ref_id="CVE-2011-4077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4132" ref_id="CVE-2011-4132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4622" ref_id="CVE-2011-4622"/>
        <description>[2.6.32-300.11.1.el6uek] - [fs] xfs: Fix possible memory corruption in
          xfs_readlink (Carlos Maiolino) {CVE-2011-4077} - [scsi] increase qla2xxx firmware ready
          time-out (Joe Jin) - [scsi] qla2xxx: Module parameter to control use of async or sync port
          login (Joe Jin) - [net] tg3: Fix single-vector MSI-X code (Joe Jin) - [net] qlge: fix size
          of external list for TX address descriptors (Joe Jin) - [net] e1000e: Avoid wrong check on
          TX hang (Joe Jin) - crypto: ghash - Avoid null pointer dereference if no key is set (Nick
          Bowler) {CVE-2011-4081} - jbd/jbd2: validate sb->s_first in journal_get_superblock()
          (Eryu Guan) {CVE-2011-4132} - KVM: Device assignment permission checks (Joe Jin)
          {CVE-2011-4347} - KVM: x86: Prevent starting PIT timers in the absence of irqchip support
          (Jan Kiszka) {CVE-2011-4622} - xfs: validate acl count (Joe Jin) {CVE-2012-0038} - KVM:
          x86: fix missing checks in syscall emulation (Joe Jin) {CVE-2012-0045} - KVM: x86: extend
          'struct x86_emulate_ops' with 'get_cpuid' (Joe Jin) {CVE-2012-0045} - igmp: Avoid zero
          delay when receiving odd mixture of IGMP queries (Ben Hutchings) {CVE-2012-0207} - ipv4:
          correct IGMP behavior on v3 query during v2-compatibility mode (David Stevens) - fuse: fix
          fuse request unique id (Srinivas Eeda) [orabug 13816349]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:11.239-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:49.386-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:13.281-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132608 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:40.164-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:38.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:131662"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132631"/>
            <criterion comment="ofa-2.6.32-300.11.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132480"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132578"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132545"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132476"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132162"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:131840"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132335"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132588"/>
            <criterion comment="ofa-2.6.32-300.11.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132608"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132180"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132657"/>
            <criterion comment="ofa-2.6.32-300.11.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132274"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:131957"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132488"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132303"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132540"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132499"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:131751"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131729"/>
            <criterion comment="ofa-2.6.32-300.11.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132280"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27912" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0480 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0480.html" ref_id="ELSA-2012-0480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1583" ref_id="CVE-2012-1583"/>
        <description>[2.6.18-308.4.1.el5]

- [net] ipv6: fix skb double free in xfrm6_tunnel (Jiri Benc) [752305 743375] {CVE-2012-1583}



[2.6.18-308.3.1.el5]

- [net] be2net: cancel be_worker during EEH recovery (Ivan Vecera) [805462 773735]

- [net] be2net: add vlan/rx-mode/flow-control config to be_setup (Ivan Vecera) [805462 773735]

- [x86] disable TSC synchronization when using kvmclock (Marcelo Tosatti) [805460 799170]

- [fs] vfs: fix LOOKUP_DIRECTORY not propagated to managed_dentry (Ian Kent) [801726 798809]

- [fs] vfs: fix d_instantiate_unique (Ian Kent) [801726 798809]

- [fs] nfs: allow high priority COMMITs to bypass inode commit lock (Jeff Layton) [799941 773777]

- [fs] nfs: don't skip COMMITs if system under is mem pressure (Jeff Layton) [799941 773777]

- [scsi] qla2xxx: Read the HCCR register to flush any PCIe writes (Chad Dupuis) [798748 772192]

- [scsi] qla2xxx: Complete mbox cmd timeout before next reset cycle (Chad Dupuis) [798748 772192]

- [s390] qdio: wrong buffers-used counter for ERROR buffers (Hendrik Brueckner) [801724 790840]

- [net] bridge: Reset IPCB when entering IP stack (Herbert Xu) [804721 749813]

- [fs] procfs: add hidepid= and gid= mount options (Jerome Marchand) [770649 770650]

- [fs] procfs: parse mount options (Jerome Marchand) [770649 770650]



[2.6.18-308.2.1.el5]

- [fs] nfs: nfs_fhget should wait on I_NEW instead of I_LOCK (Sachin Prabhu) [795664 785062]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:23.077-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:49.232-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:13.156-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:26:36.914-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:26:36.914-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132519"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.4.1.el5-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132590"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.4.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132144"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132134"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:131834"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132579"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132587"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132235"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132470"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132360"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:131958"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:132387"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.4.1.el5PAE-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132382"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.4.1.el5debug-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132432"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.4.1.el5xen-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132397"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.4.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132503"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.4.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132001"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.4.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27907" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0088 -- kvm security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0088.html" ref_id="ELSA-2010-0088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0297" ref_id="CVE-2010-0297"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0298" ref_id="CVE-2010-0298"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0306" ref_id="CVE-2010-0306"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0309" ref_id="CVE-2010-0309"/>
        <description>[kvm-83-105.0.1.el5_4.22]
- Add kvm-add-oracle-workaround-for-libvirt-bug.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:50.664-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:48.840-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:12.969-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:06:35.050-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:06:35.050-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-105.0.1.el5_4.22" test_ref="oval:org.mitre.oval:tst:135077"/>
          <criterion comment="kmod-kvm is earlier than 0:83-105.0.1.el5_4.22" test_ref="oval:org.mitre.oval:tst:135275"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-105.0.1.el5_4.22" test_ref="oval:org.mitre.oval:tst:134766"/>
          <criterion comment="kvm-tools is earlier than 0:83-105.0.1.el5_4.22" test_ref="oval:org.mitre.oval:tst:134458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27905" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0370 -- xen security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0370.html" ref_id="ELSA-2012-0370"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0029" ref_id="CVE-2012-0029"/>
        <description>[3.0.3-135.el5_8.2]
- Fix broken timestamp log (rhbz 797836)

[3.0.3-135.el5_8.1]
- qemu-dm/e1000: bounds packet size against buffer size (rhbz 786862)
- Use correct expansion in xen-network-common.sh (rhbz 797191)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:06.161-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:48.586-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:12.765-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:30:41.153-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:30:41.153-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.2" test_ref="oval:org.mitre.oval:tst:132633"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.2" test_ref="oval:org.mitre.oval:tst:132606"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.2" test_ref="oval:org.mitre.oval:tst:132712"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27903" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2021 -- Oracle Linux 6 Unbreakable Enterprise kernel security fix update
          (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2021.html" ref_id="ELSA-2011-2021"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1767" ref_id="CVE-2011-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1768" ref_id="CVE-2011-1768"/>
        <description>[2.6.32-100.37.1.el6uek] - [net] gre: fix netns vs proto registration ordering
          {CVE-2011-1767} - [net] tunnels: fix netns vs proto registration ordering
          {CVE-2011-1768}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:28.656-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:48.099-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:12.466-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36745 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:36.347-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:37.646-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133249"/>
            <criterion comment="ofa-2.6.32-100.37.1.el5uek is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133130"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133665"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133704"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:132744"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133685"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133090"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133425"/>
            <criterion comment="ofa-2.6.32-100.37.1.el5uekdebug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133548"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133452"/>
            <criterion comment="ofa-2.6.32-100.37.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133638"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:132843"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133300"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133720"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133740"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133586"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133651"/>
            <criterion comment="ofa-2.6.32-100.37.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133524"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27902" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0501 -- firefox security, bug fix, and enhancement update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>devhelp</product>
          <product>esc</product>
          <product>firefox</product>
          <product>gnome-python2-extras</product>
          <product>totem</product>
          <product>xulrunner</product>
          <product>yelp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0501.html" ref_id="ELSA-2010-0501"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5017" ref_id="CVE-2009-5017"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0182" ref_id="CVE-2010-0182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1121" ref_id="CVE-2010-1121"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1125" ref_id="CVE-2010-1125"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1196" ref_id="CVE-2010-1196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1197" ref_id="CVE-2010-1197"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1198" ref_id="CVE-2010-1198"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1199" ref_id="CVE-2010-1199"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1200" ref_id="CVE-2010-1200"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1202" ref_id="CVE-2010-1202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1203" ref_id="CVE-2010-1203"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5913" ref_id="CVE-2008-5913"/>
        <description>Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2010-1121, CVE-2010-1200, CVE-2010-1202, CVE-2010-1203)

A flaw was found in the way browser plug-ins interact. It was possible for
a plug-in to reference the freed memory from a different plug-in, resulting
in the execution of arbitrary code with the privileges of the user running
Firefox. (CVE-2010-1198)

Several integer overflow flaws were found in the processing of malformed
web content. A web page containing malicious content could cause Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2010-1196, CVE-2010-1199)

A focus stealing flaw was found in the way Firefox handled focus changes. A
malicious website could use this flaw to steal sensitive data from a user,
such as usernames and passwords. (CVE-2010-1125)

A flaw was found in the way Firefox handled the "Content-Disposition:
attachment" HTTP header when the "Content-Type: multipart" HTTP header was
also present. A website that allows arbitrary uploads and relies on the
"Content-Disposition: attachment" HTTP header to prevent content from being
displayed inline, could be used by an attacker to serve malicious content
to users. (CVE-2010-1197)

A flaw was found in the Firefox Math.random() function. This function could
be used to identify a browsing session and track a user across different
websites. (CVE-2008-5913)

A flaw was found in the Firefox XML document loading security checks.
Certain security checks were not being called when an XML document was
loaded. This could possibly be leveraged later by an attacker to load
certain resources that violate the security policies of the browser or its
add-ons. Note that this issue cannot be exploited by only loading an XML
document. (CVE-2010-0182)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:59.306-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:46.614-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:11.930-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:40:29.421-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:40:29.421-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="devhelp is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:135057"/>
          <criterion comment="esc is earlier than 0:1.1.0-12.el5" test_ref="oval:org.mitre.oval:tst:134526"/>
          <criterion comment="firefox is earlier than 0:3.6.4-8.0.1.el5" test_ref="oval:org.mitre.oval:tst:134501"/>
          <criterion comment="gnome-python2-extras is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:135040"/>
          <criterion comment="totem is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:134774"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.4-9.0.1.el5" test_ref="oval:org.mitre.oval:tst:134989"/>
          <criterion comment="yelp is earlier than 0:2.16.0-26.el5" test_ref="oval:org.mitre.oval:tst:135043"/>
          <criterion comment="devhelp-devel is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:134645"/>
          <criterion comment="gnome-python2-gtkhtml2 is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:135004"/>
          <criterion comment="gnome-python2-gtkmozembed is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:135129"/>
          <criterion comment="gnome-python2-gtkspell is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:134921"/>
          <criterion comment="gnome-python2-libegg is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:135088"/>
          <criterion comment="totem-devel is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:134937"/>
          <criterion comment="totem-mozplugin is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:135075"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.4-9.0.1.el5" test_ref="oval:org.mitre.oval:tst:134826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27901" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0428 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0428.html" ref_id="ELSA-2012-0428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4128" ref_id="CVE-2011-4128"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1569" ref_id="CVE-2012-1569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1573" ref_id="CVE-2012-1573"/>
        <description>[1.4.1-7.2]
- fix CVE-2011-4128 - buffer overflow in gnutls_session_get_data() (#752308)
- fix CVE-2012-1569 - missing length check when decoding DER lengths (#804920)
- fix CVE-2012-1573 - security issue in packet parsing (#805432)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:07.304-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:46.508-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:11.826-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:10:19.845-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:10:19.845-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:132538"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:132394"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:132468"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27896" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1459 -- bind97 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1459.html" ref_id="ELSA-2011-1459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313" ref_id="CVE-2011-4313"/>
        <description>[32:9.7.0-6.P2.4]
- fix DOS against recursive servers (#754398)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:34.182-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:45.988-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:11.556-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:28:47.518-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:28:47.518-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 0:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:133289"/>
          <criterion comment="bind97-chroot is earlier than 0:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:133292"/>
          <criterion comment="bind97-devel is earlier than 0:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:133320"/>
          <criterion comment="bind97-libs is earlier than 0:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:132656"/>
          <criterion comment="bind97-utils is earlier than 0:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:133281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27892" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0306 -- krb5 security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0306.html" ref_id="ELSA-2012-0306"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1526" ref_id="CVE-2011-1526"/>
        <description>[1.6.1-70.el5]
- add upstream patch for telnetd buffer overflow (CVE-2011-4862, #770351)

[1.6.1-69.el5]
- ftp: fix a static analysis should-never-happen NULL dereference (#750823)

[1.6.1-68.el5]
- backport fixes to teach libkrb5 to use descriptors higher than FD_SETSIZE
  to talk to a KDC by using poll() if it's detected at compile-time, revised
  (#701444, RT#6905)

[1.6.1-67.el5]
- add backported patch by way of jbarbuc to free subkeys created by the
  KDC while processing TGS requests (#708516)

[1.6.1-66.el5]
- add backported patch by way of several people to better avoid false
  detection of replay attacks when talking to systems with coarse time
  resolution (#713500)

[1.6.1-65.el5]
- ftpd: add backported patch to check for errors when calling setegid
  (MITKRB5-SA-2011-005, CVE-2011-1526, #719098)

[1.6.1-64.el5]
- klist: don't trip over referral entries when invoked with -s (#729067,
  RT#6915)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:02.188-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:44.916-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.999-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:15:45.857-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:15:45.857-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:132673"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:132081"/>
          <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:132318"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:132469"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:132694"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:132154"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27891" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0661 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0661.html" ref_id="ELSA-2010-0661"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2240" ref_id="CVE-2010-2240"/>
        <description>[2.6.18-194.11.3.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) [orabug 9504524]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)
  [orabug 9245919]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson) 
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson) 
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro, 
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]

[2.6.18-194.11.3.el5]
- [mm] accept an abutting stack segment (Jiri Pirko) [607857 607858] {CVE-2010-2240}

[2.6.18-194.11.2.el5]
- [mm] pass correct mm when growing stack (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] fix up some user-visible effects of stack guard page (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] fix page table unmap for stack guard page properly (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] fix missing unmap for stack guard page failure case (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] keep a guard page below a grow-down stack segment (Jiri Pirko) [607857 607858] {CVE-2010-2240}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:03.298-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:44.639-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.840-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:40:11.513-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:40:11.513-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134970"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.3.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:135025"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.3.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134814"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134777"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134799"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134535"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134350"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134984"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134969"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:134930"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:135023"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.3.0.1.el5" test_ref="oval:org.mitre.oval:tst:135003"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.3.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134977"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.3.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134955"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.3.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134806"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.3.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134264"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.3.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134339"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.3.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27889" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0007 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0007.html" ref_id="ELSA-2012-0007"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020" ref_id="CVE-2011-1020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3637" ref_id="CVE-2011-3637"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4077" ref_id="CVE-2011-4077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4132" ref_id="CVE-2011-4132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4324" ref_id="CVE-2011-4324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4325" ref_id="CVE-2011-4325"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4330" ref_id="CVE-2011-4330"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4348" ref_id="CVE-2011-4348"/>
        <description>[2.6.18-274.17.1.0.1.el5]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [scsi] add additional scsi medium error handling (John Sobecki) [orabug 12904887]
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- bonding: reread information about speed and duplex when interface goes up (John Haxby) [orabug 11890822]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:01.526-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:43.656-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.481-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:04:46.714-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:04:46.714-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132963"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.17.1.0.1.el5-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132831"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.17.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132959"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132746"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132889"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132837"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132881"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132877"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132883"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132523"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132870"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132864"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.17.1.0.1.el5PAE-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132206"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.17.1.0.1.el5debug-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132846"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.17.1.0.1.el5xen-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132885"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.17.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132847"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.17.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133024"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.17.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132918"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27882" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0313 -- samba security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0313.html" ref_id="ELSA-2012-0313"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926" ref_id="CVE-2010-0926"/>
        <description>[3.0.33-3.37.el5]
- Regenerate manpage for 'wide links' and 'unix extensions' sections
- related: #722553

[3.0.33-3.36.el5]
- Security Release, fixes CVE-2010-0926
- resolves: #722553

[3.0.33-3.35.el5]
- Fix smbclient return code
- resolves: #768908

[3.0.33-3.34.el5]
- Fix support for Windows 2008 R2 domains
- resolves: #736124

[3.0.33-3.33.el5]
- Security Release, fixes CVE-2010-0547, CVE-2010-0787, CVE-2011-2694,
  CVE-2011-2522, CVE-2011-1678, CVE-2011-2724
- resolves: #722553

[3.0.33-3.32.el5]
- Security Release, fixes CVE-2011-0719
- resolves: #678331

[3.0.33-3.30.el5]
- Security Release, fixes CVE-2010-3069
- resolves: #632230</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:02.415-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:42.045-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.687-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:01:26.096-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:01:26.096-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:132420"/>
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:132461"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:132465"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:132677"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:132349"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:132380"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27881" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0166 -- gnutls security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0166.html" ref_id="ELSA-2010-0166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409" ref_id="CVE-2009-2409"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" ref_id="CVE-2009-3555"/>
        <description>[1.4.1-3.8]
- fix safe renegotiation on SSL3 protocol

[1.4.1-3.7]
- implement safe renegotiation - CVE-2009-3555 (#533125)
- do not allow MD2 in certificate signatures by default - CVE-2009-2409
  (#510197)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:14.434-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:41.841-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.582-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:42:35.064-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:42:35.064-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:135110"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:135281"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:135125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27879" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0051 -- kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0051.html" ref_id="ELSA-2012-0051"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0029" ref_id="CVE-2012-0029"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4622" ref_id="CVE-2011-4622"/>
        <description>[kvm-83-239.0.1.el5_7.1]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch

[kvm-83-239.el5_7.1]
- kvm-e1000-prevent-buffer-overflow-when-processing-legacy.patch [bz#772079]
- Resolves: bz#772079
  (EMBARGOED CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [rhel-5.7.z])
- kvm-Fix-external-module-compat.c-not-to-use-unsupported-.patch [bz#753860]
  (build fix)
- kvm-kernel-KVM-x86-Prevent-starting-PIT-timers-in-the-absence-o.patch [bz#770100]
- Resolves: bz#770100
  (CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [rhel-5.7.z])

[kvm-83-239.el5_7.1]
- Updated kversion to 2.6.18-274.17.1.el5 to match build root</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:15.824-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:41.563-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.408-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:59:06.296-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:59:06.296-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-239.0.1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132856"/>
          <criterion comment="kmod-kvm is earlier than 0:83-239.0.1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132737"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-239.0.1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132764"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-239.0.1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132370"/>
          <criterion comment="kvm-tools is earlier than 0:83-239.0.1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132808"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27877" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-0150-1 -- Oracle Linux 5.8 kernel security and bug update
          (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0150-1.html" ref_id="ELSA-2012-0150-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083" ref_id="CVE-2011-1083"/>
        <description>A flaw was found in the way the Linux kernel's Event Poll (epoll) subsystem
          handled large, nested epoll structures. A local, unprivileged user could use this flaw to
          cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:21.053-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:41.361-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.256-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36005 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:37.689-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:37.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132334"/>
          <criterion comment="ocfs2-2.6.18-308.0.0.0.1.el5 is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132634"/>
          <criterion comment="oracleasm-2.6.18-308.0.0.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132299"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132659"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132486"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132722"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132643"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132628"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132147"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132702"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132698"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:132667"/>
          <criterion comment="ocfs2-2.6.18-308.0.0.0.1.el5PAE is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132298"/>
          <criterion comment="ocfs2-2.6.18-308.0.0.0.1.el5debug is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132638"/>
          <criterion comment="ocfs2-2.6.18-308.0.0.0.1.el5xen is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132377"/>
          <criterion comment="oracleasm-2.6.18-308.0.0.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132601"/>
          <criterion comment="oracleasm-2.6.18-308.0.0.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132449"/>
          <criterion comment="oracleasm-2.6.18-308.0.0.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132674"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27876" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1116 -- perl-DBD-Pg security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1116.html" ref_id="ELSA-2012-1116"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1151" ref_id="CVE-2012-1151"/>
        <description>[2.15.1-4]
- Resolves: rhbz#841131 (CVE-2012-1151)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:21.659-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:41.182-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.150-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:50:26.375-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:50:26.375-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="perl-DBD-Pg is earlier than 0:1.49-4.el5_8" test_ref="oval:org.mitre.oval:tst:131473"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="perl-DBD-Pg is earlier than 0:2.15.1-4.el6_3" test_ref="oval:org.mitre.oval:tst:130574"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27874" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0723 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0723.html" ref_id="ELSA-2010-0723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1083" ref_id="CVE-2010-1083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2492" ref_id="CVE-2010-2492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2798" ref_id="CVE-2010-2798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2938" ref_id="CVE-2010-2938"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2942" ref_id="CVE-2010-2942"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2943" ref_id="CVE-2010-2943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3015" ref_id="CVE-2010-3015"/>
        <description>[2.6.18-194.17.1.0.1.el5]

- [xen] check to see if hypervisor supports memory reservation change

  (Chuck Anderson) [orabug 7556514]

- Add entropy support to igb (John Sobecki) [orabug 7607479]

- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]

- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]

  [bz 7258]

- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]

- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]

- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)

  [orabug 7579314]

- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]

- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) 

  [orabug 9504524]

- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]

  RDS: Fix BUG_ONs to not fire when in a tasklet

  ipoib: Fix lockup of the tx queue

  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)

  RDS: Properly unmap when getting a remote access error (Tina Yang)

  RDS: Fix locking in rds_send_drop_to()

- [mm] Enhance shrink_zone patch allow full swap utilization, and also be

  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)

  [orabug 9245919]

- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)

  [orabug 9107465]

- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)

  [orabug 9764220]

- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]

- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,

  Guru Anbalagane) [orabug 6124033]

- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]

- [ib] fix memory corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:53.825-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:40.659-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.861-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:42:27.837-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:42:27.837-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134905"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.1.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134858"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134895"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134823"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134540"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134903"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134667"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134920"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134803"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134714"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134849"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134843"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.1.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134881"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.1.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134865"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.17.1.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134343"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134570"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134688"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.17.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27873" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0324 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0324.html" ref_id="ELSA-2012-0324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0841" ref_id="CVE-2012-0841"/>
        <description>[2.7.6-4.0.1.el6_2.4]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-4.el6_2.4]
- remove chunk in patch related to configure.in as it breaks rebuild
- Resolves: rhbz#788845

[2.7.6-4.el6_2.3]
- fix previous build to force compilation of randomization code
- Resolves: rhbz#788845

[2.7.6-4.el6_2.2]
- adds randomization to hash and dict structures CVE-2012-0841
- Resolves: rhbz#788845</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:27.024-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:40.539-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.781-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:00:38.346-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:00:38.346-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.0.1.el5_8.2" test_ref="oval:org.mitre.oval:tst:132330"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.0.1.el5_8.2" test_ref="oval:org.mitre.oval:tst:132615"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.0.1.el5_8.2" test_ref="oval:org.mitre.oval:tst:132464"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132614"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132725"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132717"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132629"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27872" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0717 -- bind97 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0717.html" ref_id="ELSA-2012-0717"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1033" ref_id="CVE-2012-1033"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1667" ref_id="CVE-2012-1667"/>
        <description>[32:9.7.0-10.P2.1]
- fix CVE-2012-1667 and CVE-2012-1033</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:18.302-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:40.430-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.707-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:02:07.792-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:02:07.792-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 0:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:131678"/>
          <criterion comment="bind97-chroot is earlier than 0:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:131212"/>
          <criterion comment="bind97-devel is earlier than 0:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:131868"/>
          <criterion comment="bind97-libs is earlier than 0:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:131889"/>
          <criterion comment="bind97-utils is earlier than 0:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:131872"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27865" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0927 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0927.html" ref_id="ELSA-2011-0927"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4649" ref_id="CVE-2010-4649"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0695" ref_id="CVE-2011-0695"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711" ref_id="CVE-2011-0711"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1044" ref_id="CVE-2011-1044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1182" ref_id="CVE-2011-1182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1573" ref_id="CVE-2011-1573"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576" ref_id="CVE-2011-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1593" ref_id="CVE-2011-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1745" ref_id="CVE-2011-1745"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1746" ref_id="CVE-2011-1746"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1776" ref_id="CVE-2011-1776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1936" ref_id="CVE-2011-1936"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2022" ref_id="CVE-2011-2022"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2213" ref_id="CVE-2011-2213"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2492" ref_id="CVE-2011-2492"/>
        <description>[2.6.18-238.19.1.0.1.el5]
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- bonding: reread information about speed and duplex when interface goes up (John Haxby) [orabug 11890822]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- fix missing aio_complete() in end_io (Joel Becker) [orabug 10365195]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [nfs] too many getattr and access calls after direct I/O [orabug 9348191]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:18.050-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:38.282-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:07.870-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:25:41.958-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:25:41.958-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133698"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.19.1.0.1.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133652"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.19.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133723"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133650"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133624"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133546"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133287"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133487"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133628"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133667"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133057"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.19.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133601"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.19.1.0.1.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133319"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.19.1.0.1.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133519"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.19.1.0.1.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133507"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.19.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133225"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.19.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133394"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.19.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27863" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1088 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1088.html" ref_id="ELSA-2012-1088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1948" ref_id="CVE-2012-1948"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1950" ref_id="CVE-2012-1950"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1951" ref_id="CVE-2012-1951"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1952" ref_id="CVE-2012-1952"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1953" ref_id="CVE-2012-1953"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1954" ref_id="CVE-2012-1954"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1955" ref_id="CVE-2012-1955"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1957" ref_id="CVE-2012-1957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1958" ref_id="CVE-2012-1958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1959" ref_id="CVE-2012-1959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1961" ref_id="CVE-2012-1961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1962" ref_id="CVE-2012-1962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1963" ref_id="CVE-2012-1963"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1964" ref_id="CVE-2012-1964"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1965" ref_id="CVE-2012-1965"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1966" ref_id="CVE-2012-1966"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1967" ref_id="CVE-2012-1967"/>
        <description>firefox
[10.0.6-1.0.1.el6_3]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.6-1]
- Update to 10.0.6 ESR

[10.0.5-3]
- Enabled WebM

[10.0.5-2]
- Added fix for mozbz#703633, rhbz#818341

xulrunner
[10.0.6-1.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.6-1]
- Update to 10.0.6 ESR

[10.0.5-3]
- Added fix for rhbz#808136 (mozbz#762301)

[10.0.5-2]
- Enabled WebM (rhbz#798880)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:30.485-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:36.257-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:07.191-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:17:27.747-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:17:27.747-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.6-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131483"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131597"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130662"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.6-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131528"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130967"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131647"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27862" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0152 -- kexec-tools security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kexec-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0152.html" ref_id="ELSA-2012-0152"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3588" ref_id="CVE-2011-3588"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3589" ref_id="CVE-2011-3589"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3590" ref_id="CVE-2011-3590"/>
        <description>[1.102pre-154.0.3]
- mkdumprd.orig get packed, remove it.

[1.102pre-154.0.2]
- fix mounting root fs on labeled disk (Maxim Uvarov) [orabug: 13709374]

[1.102pre-154.0.1]
Merge following patches from mkinitrd:
- mkinitrd-fix-san-boot.patch
- mkinitrd-fix-shared-lib-library-path.patch
- mkinitrd-5.1.19.6-libfirmware-subdir-include.patch
- mkinitrd-fix-setquiet-for-non-verbose.patch
- add-option-to-forceload-multipath.patch
- Update kexec-kdump-howto.txt with Oracle references
- Add mkdumprd load firmware support [orabug 10432768]
- Updated makedumpfile to el6 version (Herbert van den Bergh) [orabug 10088607]
- Merged UEK modification,Updated Source1 kdump.init
  Added --allow-missing for rebuilding kdump_initrd
- Updated kexec-kdump-howto.txt with Oracle references</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:22.042-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:36.141-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:07.111-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:51:56.234-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:51:56.234-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="kexec-tools is earlier than 0:1.102pre-154.0.3.el5" test_ref="oval:org.mitre.oval:tst:132413"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27857" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1054 -- libtiff security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1054.html" ref_id="ELSA-2012-1054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2088" ref_id="CVE-2012-2088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2113" ref_id="CVE-2012-2113"/>
        <description>[3.9.4-6]
- Add fixes for CVE-2012-2088, CVE-2012-2113
Resolves: #835748</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:26.716-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:35.463-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:06.794-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:23:54.056-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:23:54.056-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:131366"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:131428"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:131592"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:131209"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:130780"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27855" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0467 -- freetype security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0467.html" ref_id="ELSA-2012-0467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1126" ref_id="CVE-2012-1126"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1127" ref_id="CVE-2012-1127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1130" ref_id="CVE-2012-1130"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1131" ref_id="CVE-2012-1131"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1132" ref_id="CVE-2012-1132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1134" ref_id="CVE-2012-1134"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1136" ref_id="CVE-2012-1136"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1137" ref_id="CVE-2012-1137"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1139" ref_id="CVE-2012-1139"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1140" ref_id="CVE-2012-1140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1141" ref_id="CVE-2012-1141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1142" ref_id="CVE-2012-1142"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1143" ref_id="CVE-2012-1143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1144" ref_id="CVE-2012-1144"/>
        <description>[2.3.11-6.el6_2.9]
- Fix CVE-2012-{1126, 1127, 1130, 1131, 1132, 1134, 1136,
  1137, 1139, 1140, 1141, 1142, 1143, 1144}
- Properly initialize array 'result' in
  FT_Outline_Get_Orientation()
- Check bytes per row for overflow in _bdf_parse_glyphs()
- Resolves: #806268</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:29.366-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:32.978-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.974-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:41:52.548-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:41:52.548-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:132074"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:132513"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:132386"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:132212"/>
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:132399"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:132585"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27854" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0196 -- php53 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0196.html" ref_id="ELSA-2011-0196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3710" ref_id="CVE-2010-3710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4156" ref_id="CVE-2010-4156"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4645" ref_id="CVE-2010-4645"/>
        <description>[5.3.3-1.1]
- add security fixes for CVE-2010-3710, CVE-2010-4156,
  CVE-2010-4645 (#670463)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:57.280-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:32.446-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.727-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:08:12.761-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:08:12.761-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php53 is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:133995"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134168"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134677"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134682"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134742"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134740"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134626"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134471"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134583"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134275"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134575"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134699"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134246"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134642"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134175"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134405"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134520"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134549"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134258"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134532"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134412"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27850" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0677 -- postgresql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0677.html" ref_id="ELSA-2012-0677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0866" ref_id="CVE-2012-0866"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0868" ref_id="CVE-2012-0868"/>
        <description>[8.1.23-4]
- Back-port upstream fixes for CVE-2012-0866 and CVE-2012-0868
Resolves: #812070

[8.1.23-3]
- Back-port upstream fix for unregistering OpenSSL callbacks at close
Resolves: #728828

[8.1.23-2]
- Back-port upstream fix for CVE-2011-2483
Resolves: #740738</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:06.723-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:31.838-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.395-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:50:12.735-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:50:12.735-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132218"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132038"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132150"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132241"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132234"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132112"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132262"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:131913"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:131408"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:132186"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27847" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0237 -- sendmail security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sendmail</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0237.html" ref_id="ELSA-2010-0237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7176" ref_id="CVE-2006-7176"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4565" ref_id="CVE-2009-4565"/>
        <description>[8.13.8-8]

- rpm attributes S,5,T not recorded for statistics file

[8.13.8-7]
- fix specfile for passing rpm -V test (#555277)

[8.13.8-6.el5]
- fix verification of SSL certificate with NUL in name (#553618, CVE-2009-4565)
- do not accept localhost.localdomain as valid address from smtp (#449391)
- skip colon separator when parsing service name in ServiceSwitchFile (#512871)
- exit with non-zero error code when free space is low (#299951)
- fix -qG description in man page (#250552)
- fix comments in sendmail.mc to use correct certs path (#244012)
- add MTA to provides (#494408)
- fix %dist macro use (#440616)
- compile with -fno-strict-aliasing
- skip t-sem test as it doesn't allow parallel testing</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:54.239-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:30.892-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.055-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:19:50.274-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:19:50.274-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sendmail is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:135193"/>
          <criterion comment="sendmail-cf is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:135279"/>
          <criterion comment="sendmail-devel is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:135186"/>
          <criterion comment="sendmail-doc is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:134840"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27845" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1097 -- glibc security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1097.html" ref_id="ELSA-2012-1097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3406" ref_id="CVE-2012-3406"/>
        <description>[2.5-81.el5_8.4]
- Fix iconv() segfault if the invalid multibyte character 0xffff is input when converting from IBM930 (#837896)

[2.5-81.el5_8.3]
- Fix unbound alloca in vfprintf (#833720)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:36.266-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:30.628-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.924-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:31:26.357-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:31:26.357-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:131544"/>
          <criterion comment="glibc-common is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:131327"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:131261"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:131529"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:131562"/>
          <criterion comment="nscd is earlier than 0:2.5-81.el5_8.4" test_ref="oval:org.mitre.oval:tst:131556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27844" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1130 -- xen security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1130.html" ref_id="ELSA-2012-1130"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2625" ref_id="CVE-2012-2625"/>
        <description>[3.0.3-135.el5_8.4]
- pygrub: Improve handling of big files (rhbz 821704)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:12.493-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:30.389-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.826-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:53:33.407-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:53:33.407-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:131342"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:130791"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:131484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27842" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2001 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
          <product>mlnx_en</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2001.html" ref_id="ELSA-2012-2001"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0056" ref_id="CVE-2012-0056"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2962" ref_id="CVE-2010-2962"/>
        <description>[2.6.32-300.7.1.el6uek] - Revert "proc: enable writing to /proc/pid/mem"
          [orabug 13619701] {CVE-2012-0056} - [PATCH] x86, tsc: Skip TSC synchronization checks for
          tsc=reliable (Suresh Siddha) [2.6.32-300.6.1.el6uek] - tracing: Fix null pointer deref
          with SEND_SIG_FORCED (Oleg Nesterov) [orabug 13611655] [2.6.32-300.5.1.el6uek] - sched,
          x86: Avoid unnecessary overflow in sched_clock (Salman Qazi) [orabug 13604567] - [x86]:
          Don't resume/restore cpu if not of the expected cpu (Joe Jin) [orabug 13492670] -
          drm/i915: Rephrase pwrite bounds checking to avoid any potential overflow (Chris Wilson)
          [CVE-2010-296] - x2apic: Enable the bios request for x2apic optout (Suresh Siddha) [orabug
          13565303] - fuse: split queues to scale I/O throughput (Srinivas Eeda) [orabug 10004611] -
          fuse: break fc spinlock (Srinivas Eeda) [orabug 10004611]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:04.211-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:29.773-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.584-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36492 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:39.316-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:37.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131969"/>
            <criterion comment="ofa-2.6.32-300.7.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132355"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132632"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132857"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132620"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132378"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132327"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132661"/>
            <criterion comment="ofa-2.6.32-300.7.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132581"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132800"/>
            <criterion comment="mlnx_en-2.6.32-300.7.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132893"/>
            <criterion comment="ofa-2.6.32-300.7.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132807"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132752"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132862"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132652"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132888"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132415"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132793"/>
            <criterion comment="mlnx_en-2.6.32-300.7.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131925"/>
            <criterion comment="ofa-2.6.32-300.7.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132894"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27836" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0845 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0845.html" ref_id="ELSA-2011-0845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1910" ref_id="CVE-2011-1910"/>
        <description>[32:9.7.3-2.1.P1]

- update to 9.7.3-P1 (CVE-2011-1910)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:26.147-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:28.590-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.072-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:02:20.885-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:02:20.885-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133784"/>
            <criterion comment="bind97-chroot is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133503"/>
            <criterion comment="bind97-devel is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133758"/>
            <criterion comment="bind97-libs is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133400"/>
            <criterion comment="bind97-utils is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133510"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:132820"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133816"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133671"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133732"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133127"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:132937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27835" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0397 -- glibc security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0397.html" ref_id="ELSA-2012-0397"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0864" ref_id="CVE-2012-0864"/>
        <description>[2.5-81.el5_8.1]
- Add dist tag
[when building file lists (#784646).]
- Avoid nargs integer overflow which could be used to bypass FORTIFY_SOURCE (#794813)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:04.863-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:28.463-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:03.988-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:56:23.306-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:56:23.306-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:132471"/>
          <criterion comment="glibc-common is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:132364"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:132575"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:132455"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:132563"/>
          <criterion comment="nscd is earlier than 0:2.5-81.el5_8.1" test_ref="oval:org.mitre.oval:tst:132482"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27834" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0975 -- sssd security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0975.html" ref_id="ELSA-2011-0975"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4341" ref_id="CVE-2010-4341"/>
        <description>[1.5.1-37]
- Reverts:  rhbz#680443 - Dynamic DNS update fails if multiple servers are
-                         given in ipa_server config option</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:35.113-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:28.370-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:03.919-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:54:03.965-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:54:03.965-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sssd is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:133511"/>
          <criterion comment="sssd-client is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:132636"/>
          <criterion comment="sssd-tools is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:133415"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27829" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1482 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1482.html" ref_id="ELSA-2012-1482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4201" ref_id="CVE-2012-4201"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4202" ref_id="CVE-2012-4202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4207" ref_id="CVE-2012-4207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4209" ref_id="CVE-2012-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4210" ref_id="CVE-2012-4210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4214" ref_id="CVE-2012-4214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4215" ref_id="CVE-2012-4215"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4216" ref_id="CVE-2012-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5829" ref_id="CVE-2012-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5830" ref_id="CVE-2012-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5833" ref_id="CVE-2012-5833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5835" ref_id="CVE-2012-5835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5839" ref_id="CVE-2012-5839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5840" ref_id="CVE-2012-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5841" ref_id="CVE-2012-5841"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5842" ref_id="CVE-2012-5842"/>
        <description>firefox
[10.0.11-1.0.1.el6_3]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[10.0.11-1]
- Update to 10.0.11 ESR

xulrunner
[10.0.11-1.0.1.el6_3]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.11-1]
- Update to 10.0.11 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:27.316-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:25.233-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.830-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:10:57.327-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:10:57.327-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130690"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130828"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130447"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130710"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130728"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130642"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27823" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-0480-1 -- kernel security, bug fix, and enhancement update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0480-1.html" ref_id="ELSA-2012-0480-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1583" ref_id="CVE-2012-1583"/>
        <description>[2.6.18-308.4.1.0.1.el5] - [net] bonding: fix carrier detect when bond is down
          [orabug 12377284] - [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075] - fix
          ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use
          dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0
          reset when hvm boot up with noapic param - [scsi] remove printk's when doing I/O to a dead
          device (John Sobecki, Chris Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to
          timing problems (Joe Jin) [orabug 12561346] - [scsi] Fix race when removing SCSI devices
          (Joe Jin) [orabug 12404566] - [net] net: Redo the broken redhat netconsole over bonding
          (Tina Yang) [orabug 12740042] - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic
          (Joe Jin) [orabug 12687646] - [scsi] fix scsi hotplug and rescan race [orabug 10260172] -
          fix filp_close() race (Joe Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default
          [orabug 67188919] - [xen] check to see if hypervisor supports memory reservation change
          (Chuck Anderson) [orabug 7556514] - [net] Enable entropy for
          bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki) [orabug 10315433] - [NET] Add xen
          pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258] - [mm] shrink_zone patch
          (John Sobecki,Chris Mason) [orabug 6086839] - fix aacraid not to reset during kexec (Joe
          Jin) [orabug 8516042] - [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572,
          9344105] RDS: Fix BUG_ONs to not fire when in a tasklet ipoib: Fix lockup of the tx queue
          RDS: Do not call set_page_dirty() with irqs off (Sherman Pun) RDS: Properly unmap when
          getting a remote access error (Tina Yang) RDS: Fix locking in rds_send_drop_to() - [xen]
          PVHVM guest with PoD crashes under memory pressure (Chuck Anderson) [orabug 9107465] -
          [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson) [orabug 9764220] -
          Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615] - fix overcommit
          memory to use percpu_counter for el5 (KOSAKI Motohiro, Guru Anbalagane) [orabug 6124033] -
          [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208] - [ib] fix memory
          corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:12.650-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:24.238-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.306-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:131716 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:38.131-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:34.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132428"/>
          <criterion comment="ocfs2-2.6.18-308.4.1.0.1.el5 is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132477"/>
          <criterion comment="oracleasm-2.6.18-308.4.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132533"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132441"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131954"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132305"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132556"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132456"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132500"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132343"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132170"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132414"/>
          <criterion comment="ocfs2-2.6.18-308.4.1.0.1.el5PAE is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132546"/>
          <criterion comment="ocfs2-2.6.18-308.4.1.0.1.el5debug is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132516"/>
          <criterion comment="ocfs2-2.6.18-308.4.1.0.1.el5xen is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132543"/>
          <criterion comment="oracleasm-2.6.18-308.4.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132197"/>
          <criterion comment="oracleasm-2.6.18-308.4.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132530"/>
          <criterion comment="oracleasm-2.6.18-308.4.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131716"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27821" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0716 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0716.html" ref_id="ELSA-2012-0716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1033" ref_id="CVE-2012-1033"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1667" ref_id="CVE-2012-1667"/>
        <description>[32:9.7.3-8.P3.3]
- fix CVE-2012-1667 and CVE-2012-1033</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:04.402-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:23.535-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.031-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:56:48.840-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:56:48.840-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131621"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131928"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131390"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131967"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131253"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131826"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131813"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131670"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131757"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131367"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131627"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:132014"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131976"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131617"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27818" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-0690-1 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0690-1.html" ref_id="ELSA-2012-0690-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2136" ref_id="CVE-2012-2136"/>
        <description>[2.6.18-308.8.1.0.1.el5] - [net] bonding: fix carrier detect when bond is down
          [orabug 12377284] - [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075] - fix
          ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use
          dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0
          reset when hvm boot up with noapic param - [scsi] remove printk's when doing I/O to a dead
          device (John Sobecki, Chris Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to
          timing problems (Joe Jin) [orabug 12561346] - [scsi] Fix race when removing SCSI devices
          (Joe Jin) [orabug 12404566] - [net] net: Redo the broken redhat netconsole over bonding
          (Tina Yang) [orabug 12740042] - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic
          (Joe Jin) [orabug 12687646] - [scsi] fix scsi hotplug and rescan race [orabug 10260172] -
          fix filp_close() race (Joe Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default
          [orabug 67188919] - [xen] check to see if hypervisor supports memory reservation change
          (Chuck Anderson) [orabug 7556514] - [net] Enable entropy for
          bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki) [orabug 10315433] - [NET] Add xen
          pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258] - [mm] shrink_zone patch
          (John Sobecki,Chris Mason) [orabug 6086839] - fix aacraid not to reset during kexec (Joe
          Jin) [orabug 8516042] - [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572,
          9344105] RDS: Fix BUG_ONs to not fire when in a tasklet ipoib: Fix lockup of the tx queue
          RDS: Do not call set_page_dirty() with irqs off (Sherman Pun) RDS: Properly unmap when
          getting a remote access error (Tina Yang) RDS: Fix locking in rds_send_drop_to() - [xen]
          PVHVM guest with PoD crashes under memory pressure (Chuck Anderson) [orabug 9107465] -
          [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson) [orabug 9764220] -
          Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615] - fix overcommit
          memory to use percpu_counter for el5 (KOSAKI Motohiro, Guru Anbalagane) [orabug 6124033] -
          [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208] - [ib] fix memory
          corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:10.030-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:22.861-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.647-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:131463 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:37.898-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:33.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132171"/>
          <criterion comment="ocfs2-2.6.18-308.8.1.0.1.el5 is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132029"/>
          <criterion comment="oracleasm-2.6.18-308.8.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132178"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132125"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131860"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131711"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132156"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132148"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132184"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132207"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132167"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132163"/>
          <criterion comment="ocfs2-2.6.18-308.8.1.0.1.el5PAE is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:131963"/>
          <criterion comment="ocfs2-2.6.18-308.8.1.0.1.el5debug is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:131869"/>
          <criterion comment="ocfs2-2.6.18-308.8.1.0.1.el5xen is earlier than 0:1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:131463"/>
          <criterion comment="oracleasm-2.6.18-308.8.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131985"/>
          <criterion comment="oracleasm-2.6.18-308.8.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132057"/>
          <criterion comment="oracleasm-2.6.18-308.8.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27817" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1201 -- tetex security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tetex</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1201.html" ref_id="ELSA-2012-1201"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3702" ref_id="CVE-2010-3702"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3704" ref_id="CVE-2010-3704"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2642" ref_id="CVE-2010-2642"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0433" ref_id="CVE-2011-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0764" ref_id="CVE-2011-0764"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1552" ref_id="CVE-2011-1552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1553" ref_id="CVE-2011-1553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1554" ref_id="CVE-2011-1554"/>
        <description>[3.0-33.15.el5_9.1]
- more robust fix for CVE-2010-3702 (#773178)

[3.0-33.15]
- apply patch for CVE-2010-3702,3704 (#773180)

[3.0-33.14]
- fix CVE-2010-2642 CVE-2011-0433 CVE-2011-0764 CVE-2011-1552
  CVE-2011-1553 CVE-2011-1554, texlive various flaws (#773180)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:35.202-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:22.549-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.476-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:53:30.842-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:53:30.842-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tetex is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:131210"/>
          <criterion comment="tetex-afm is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:130976"/>
          <criterion comment="tetex-doc is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:130653"/>
          <criterion comment="tetex-dvips is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:130944"/>
          <criterion comment="tetex-fonts is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:130773"/>
          <criterion comment="tetex-latex is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:131320"/>
          <criterion comment="tetex-xdvi is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:131295"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27815" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0143 -- xulrunner security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0143.html" ref_id="ELSA-2012-0143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3026" ref_id="CVE-2011-3026"/>
        <description>[1.9.2.26-2.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with
  xulrunner-oracle-default-prefs.js

[1.9.2.26-2]
- added fix for mozbz#727401</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:16.279-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:22.184-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.302-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:29:59.908-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:29:59.908-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:132244"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:132699"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132013"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27814" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0466 -- samba3x security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0466.html" ref_id="ELSA-2012-0466"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182" ref_id="CVE-2012-1182"/>
        <description>[3.5.10-0.108]
- Security Release, fixes CVE-2012-1182
- resolves: #804650</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:15.377-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:22.033-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.211-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:44:09.639-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:44:09.639-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba3x is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:132502"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:132182"/>
          <criterion comment="samba3x-common is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:132527"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:131916"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:132433"/>
          <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:132505"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:132138"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:132202"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27813" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-0149 -- kvm security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0149.html" ref_id="ELSA-2012-0149"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4347" ref_id="CVE-2011-4347"/>
        <description>[kvm-83-249.0.1.el5]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch
- modify kversion to fix build failure

[kvm-83-249.el5]
- kvm-kernel-KVM-x86-Prevent-starting-PIT-timers-in-the-absence-o.patch [bz#770101]
- CVE: CVE-2011-4622
- Resolves: bz#770101
  (CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [rhel-5.8])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:28.170-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:21.818-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.098-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-249.0.1.el5" test_ref="oval:org.mitre.oval:tst:132637"/>
          <criterion comment="kmod-kvm is earlier than 0:83-249.0.1.el5" test_ref="oval:org.mitre.oval:tst:132315"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-249.0.1.el5" test_ref="oval:org.mitre.oval:tst:132613"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-249.0.1.el5" test_ref="oval:org.mitre.oval:tst:132696"/>
          <criterion comment="kvm-tools is earlier than 0:83-249.0.1.el5" test_ref="oval:org.mitre.oval:tst:132247"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27812" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-1445-1 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1445-1.html" ref_id="ELSA-2012-1445-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2100" ref_id="CVE-2012-2100"/>
        <description>[2.6.18-308.20.1.0.1.el5] - [kernel] Initialize the local uninitialized
          variable stats. [orabug 14051367] - [fs] JBD:make jbd support 512B blocks correctly for
          ocfs2. [orabug 13477763] - [x86 ] fix fpu context corrupt when preempt in signal context
          [orabug 14038272] - [net] bonding: fix carrier detect when bond is down [orabug 12377284]
          - [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075] - fix ia64 build error due
          to add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use dynamic vcpu_info remap to
          support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0 reset when hvm boot up with
          noapic param - [scsi] remove printks when doing I/O to a dead device (John Sobecki, Chris
          Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin)
          [orabug 12561346] - [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
          - [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
          - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646] -
          [scsi] fix scsi hotplug and rescan race [orabug 10260172] - fix filp_close() race (Joe
          Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default [orabug 67188919] - [xen]
          check to see if hypervisor supports memory reservation change (Chuck Anderson) [orabug
          7556514] - [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John
          Sobecki) [orabug 10315433] - [NET] Add xen pv netconsole support (Tina Yang) [orabug
          6993043] [bz 7258] - [mm] Patch shrink_zone to yield during severe mempressure events,
          avoiding hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839] - [mm] Enhance
          shrink_zone patch allow full swap utilization, and also be NUMA-aware (John Sobecki,Chris
          Mason,Herbert van den Bergh) [orabug 9245919] - fix aacraid not to reset during kexec (Joe
          Jin) [orabug 8516042] - [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572,
          9344105] RDS: Fix BUG_ONs to not fire when in a tasklet ipoib: Fix lockup of the tx queue
          RDS: Do not call set_page_dirty() with irqs off (Sherman Pun) RDS: Properly unmap when
          getting a remote access error (Tina Yang) RDS: Fix locking in rds_send_drop_to() - [xen]
          PVHVM guest with PoD crashes under memory pressure (Chuck Anderson) [orabug 9107465] -
          [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson) [orabug 9764220] -
          Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615] - fix overcommit
          memory to use percpu_counter for el5 (KOSAKI Motohiro, Guru Anbalagane) [orabug 6124033] -
          [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208] - [ib] fix memory
          corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:41.833-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:21.594-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:00.973-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130719 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:39.088-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:33.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130482"/>
          <criterion comment="ocfs2-2.6.18-308.20.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129924"/>
          <criterion comment="oracleasm-2.6.18-308.20.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129950"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130686"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130736"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130910"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130005"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130763"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130702"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130421"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130489"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.20.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130830"/>
          <criterion comment="ocfs2-2.6.18-308.20.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130838"/>
          <criterion comment="ocfs2-2.6.18-308.20.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130609"/>
          <criterion comment="ocfs2-2.6.18-308.20.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130917"/>
          <criterion comment="oracleasm-2.6.18-308.20.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130647"/>
          <criterion comment="oracleasm-2.6.18-308.20.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130661"/>
          <criterion comment="oracleasm-2.6.18-308.20.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130719"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27811" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0518 -- openssl security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0518.html" ref_id="ELSA-2012-0518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2110" ref_id="CVE-2012-2110"/>
        <description>openssl:
[1.0.0-20.4]
- fix for CVE-2012-2110 - memory corruption in asn1_d2i_read_bio() (#814185)

openssl098e:
[0.9.8e-17.el6_2.2]
- Updated the description

[0.9.8e-17.2]
- fix for CVE-2012-2110 - memory corruption in asn1_d2i_read_bio() (#814185)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:24.303-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:21.354-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:00.848-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:21:53.506-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:21:53.506-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:132381"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" test_ref="oval:org.mitre.oval:tst:132116"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:132237"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:132168"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:132515"/>
            <criterion comment="openssl098e is earlier than 0:0.9.8e-17.0.1.el6_2.2" test_ref="oval:org.mitre.oval:tst:132478"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:131522"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:132287"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:132497"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27810" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1385 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1385.html" ref_id="ELSA-2012-1385"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3216" ref_id="CVE-2012-3216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4416" ref_id="CVE-2012-4416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5068" ref_id="CVE-2012-5068"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5069" ref_id="CVE-2012-5069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5071" ref_id="CVE-2012-5071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5072" ref_id="CVE-2012-5072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5073" ref_id="CVE-2012-5073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5075" ref_id="CVE-2012-5075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5077" ref_id="CVE-2012-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5079" ref_id="CVE-2012-5079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5081" ref_id="CVE-2012-5081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5084" ref_id="CVE-2012-5084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5085" ref_id="CVE-2012-5085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5086" ref_id="CVE-2012-5086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5089" ref_id="CVE-2012-5089"/>
        <description>[1:1.6.0.0-1.28.1.10.10.0.1.el5_8]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.28.1.10.10]
- Updated to IcedTea6 1.10.10
- Resolves rhbz#s 856124, 865346, 865348, 865350, 865352, 865354, 865357,
  865359, 865363, 865365, 865370, 865428, 865471, 865434, 865511, 865514,
  865519, 865531, 865541, 865568</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:20.908-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:21.198-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:00.728-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:08:07.400-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:08:07.400-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.28.1.10.10.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130226"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.28.1.10.10.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130854"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.28.1.10.10.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130782"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.28.1.10.10.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130620"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.28.1.10.10.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131060"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27809" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0515 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0515.html" ref_id="ELSA-2012-0515"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0467" ref_id="CVE-2012-0467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0468" ref_id="CVE-2012-0468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0469" ref_id="CVE-2012-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0470" ref_id="CVE-2012-0470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0471" ref_id="CVE-2012-0471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0472" ref_id="CVE-2012-0472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0473" ref_id="CVE-2012-0473"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0474" ref_id="CVE-2012-0474"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0477" ref_id="CVE-2012-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0478" ref_id="CVE-2012-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0479" ref_id="CVE-2012-0479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3062" ref_id="CVE-2011-3062"/>
        <description>firefox:
[10.0.4-1.0.1.el6_2]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.4-1]
- Update to 10.0.4 ESR

xulrunner:
[10.0.4-1.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.4-1]
- Update to 10.0.4 ESR

[10.0.3-3]
- Fixed mozbz#746112 - ppc(64) freeze

[10.0.3-2]
- Fixed mozbz#681937</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:13.344-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:19.939-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:00.317-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:31:32.414-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:31:32.414-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.4-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132261"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132283"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132409"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.4-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131881"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132296"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132301"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27807" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0678 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0678.html" ref_id="ELSA-2012-0678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0867" ref_id="CVE-2012-0867"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0866" ref_id="CVE-2012-0866"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0868" ref_id="CVE-2012-0868"/>
        <description>[8.4.11-1]
- Update to PostgreSQL 8.4.11, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-10.html
  including the fixes for CVE-2012-0866, CVE-2012-0867, CVE-2012-0868
Resolves: #812081</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:27.487-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:19.189-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:59.886-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:41:00.295-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:41:00.295-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132157"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132231"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131877"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132239"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132179"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131805"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131303"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131602"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132155"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131384"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131950"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132136"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132041"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132052"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132174"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132120"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132193"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132109"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:131601"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:131739"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132128"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132217"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27806" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0833 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0833.html" ref_id="ELSA-2011-0833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726" ref_id="CVE-2011-0726"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078" ref_id="CVE-2011-1078"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079" ref_id="CVE-2011-1079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080" ref_id="CVE-2011-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1093" ref_id="CVE-2011-1093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1163" ref_id="CVE-2011-1163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1166" ref_id="CVE-2011-1166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170" ref_id="CVE-2011-1170"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171" ref_id="CVE-2011-1171"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172" ref_id="CVE-2011-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1494" ref_id="CVE-2011-1494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1495" ref_id="CVE-2011-1495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577" ref_id="CVE-2011-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1763" ref_id="CVE-2011-1763"/>
        <description>[2.6.18-238.12.1.0.1.el5]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- fix missing aio_complete() in end_io (Joel Becker) [orabug 10365195]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [nfs] too many getattr and access calls after direct I/O [orabug 9348191]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:32.871-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:18.287-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:59.504-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:10:08.757-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:10:08.757-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133259"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.12.1.0.1.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133558"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.12.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133010"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133897"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132942"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133796"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133803"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133654"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133867"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133710"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132994"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133833"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.12.1.0.1.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133868"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.12.1.0.1.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133829"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-238.12.1.0.1.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133666"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.12.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133820"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.12.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133934"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-238.12.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133021"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27805" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1258 -- quagga security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1258.html" ref_id="ELSA-2012-1258"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1674" ref_id="CVE-2010-1674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3323" ref_id="CVE-2011-3323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3324" ref_id="CVE-2011-3324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3325" ref_id="CVE-2011-3325"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3326" ref_id="CVE-2011-3326"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3327" ref_id="CVE-2011-3327"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0249" ref_id="CVE-2012-0249"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0250" ref_id="CVE-2012-0250"/>
        <description>[0.98.6-7.1]
- fix CVE-2011-3323
- fix CVE-2011-3324
- fix CVE-2011-3325
- fix CVE-2011-3326
- fix CVE-2011-3327
- fix CVE-2012-0249
- fix CVE-2010-1674

[0.98.6-7]
- Resolves: #638628 - CVE-2007-4826 CVE-2010-2948 quagga: various flaws

[0.98.6-6]
- Resolves: #528583 - Missing declarations cause zebra to segfault</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:21.490-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:17.390-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:59.200-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:01:06.262-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:01:06.262-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="quagga is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:130587"/>
          <criterion comment="quagga-contrib is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:131291"/>
          <criterion comment="quagga-devel is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:131274"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27798" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0150 -- Oracle Linux 5.8 kernel security and bug update  (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0150.html" ref_id="ELSA-2012-0150"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083" ref_id="CVE-2011-1083"/>
        <description>kernel
[2.6.18-308.el5]
- [scsi] lpfc: Update lpfc version for 8.2.0.108.4p driver release (Rob Evers) [784073]
- [scsi] lpfc: Fix FCP EQ memory check init w/single int vector (Rob Evers) [784073]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:11.951-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:15.880-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:58.301-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:13:12.037-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:13:12.037-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132715"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.el5-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132644"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132599"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132534"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132709"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:131892"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:131733"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132706"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132684"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132512"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132326"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.el5" test_ref="oval:org.mitre.oval:tst:132714"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.el5PAE-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132651"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.el5debug-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132158"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.el5xen-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132362"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132185"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132332"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27797" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1236 -- xen security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1236.html" ref_id="ELSA-2012-1236"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3515" ref_id="CVE-2012-3515"/>
        <description>[3.0.3-135.el5_8.5]
- console: Prevent escape sequence length overflow (rhbz 851253)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:39.393-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:15.778-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:58.221-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:43:44.944-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:43:44.944-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:131337"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:131329"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:131008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27795" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1140 -- dhcp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1140.html" ref_id="ELSA-2012-1140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3571" ref_id="CVE-2012-3571"/>
        <description>[12:3.0.5-31.1]
- An error in the handling of malformed client identifiers can
  cause a denial-of-service condition in affected servers. (CVE-2012-3571, #843124)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:24.779-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:15.436-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.998-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:01:33.668-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:01:33.668-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dhcp is earlier than 0:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:130995"/>
          <criterion comment="dhclient is earlier than 0:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:131322"/>
          <criterion comment="dhcp-devel is earlier than 0:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:131208"/>
          <criterion comment="libdhcp4client is earlier than 0:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:131398"/>
          <criterion comment="libdhcp4client-devel is earlier than 0:3.0.5-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:130940"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27793" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2016 -- Unbreakable Enterprise kernel security fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2016.html" ref_id="ELSA-2011-2016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4251" ref_id="CVE-2010-4251"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1023" ref_id="CVE-2011-1023"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1082" ref_id="CVE-2011-1082"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1163" ref_id="CVE-2011-1163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170" ref_id="CVE-2011-1170"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171" ref_id="CVE-2011-1171"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172" ref_id="CVE-2011-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1494" ref_id="CVE-2011-1494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1495" ref_id="CVE-2011-1495"/>
        <description>A [2.6.32-100.28.17.el6] - [net] Extend prot->slab size when add sock extend
          fields. [2.6.32-100.28.16.el6] - kernel: Fix unlimited socket backlog DoS {CVE-2010-4251}
          - RDS: Fix congestion issues for loopback - rds: prevent BUG_ON triggering on congestion
          map updates {CVE-2011-1023} - epoll: prevent creating circular epoll structures
          {CVE-2011-1082} - fs: fix corrupted OSF partition table parsing {CVE-2011-1163} - fs:
          Increase OSF partition limit from 8 to 18 {CVE-2011-1163} - netfilter: arp_tables: fix
          infoleak to userspace {CVE-2011-1170} - netfilter: ip_tables: fix infoleak to userspace
          {CVE-2011-1171} - ipv6: netfilter: ip6_tables: fix infoleak to userspace {CVE-2011-1172} -
          [SCSI] mpt2sas: prevent heap overflows and unchecked reads {CVE-2011-1494,
          CVE-2011-1495}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:56.106-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:15.284-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.896-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36860 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:42.525-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:32.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel-uek is earlier than 0:2.6.32-100.28.17.el5" test_ref="oval:org.mitre.oval:tst:133429"/>
          <criterion comment="ofa-2.6.32-100.28.17.el5 is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133675"/>
          <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.28.17.el5" test_ref="oval:org.mitre.oval:tst:133967"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.28.17.el5" test_ref="oval:org.mitre.oval:tst:134048"/>
          <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.28.17.el5" test_ref="oval:org.mitre.oval:tst:133914"/>
          <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.28.17.el5" test_ref="oval:org.mitre.oval:tst:133098"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.28.17.el5" test_ref="oval:org.mitre.oval:tst:133958"/>
          <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.28.17.el5" test_ref="oval:org.mitre.oval:tst:133926"/>
          <criterion comment="ofa-2.6.32-100.28.17.el5debug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:134039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27792" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0312 -- initscripts security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>initscripts</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0312.html" ref_id="ELSA-2012-0312"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1198" ref_id="CVE-2008-1198"/>
        <description>[8.45.42-1.0.1.el5]
- Update oracle-enterprise.patch to do detection on /etc/oracle-release 
  and /etc/enterprise-release
- Patch x86_64 sysctl.conf as well as default sysctl.conf
- Patch sysctl.conf to default rp_filter to loose reverse path
  filtering (has no effect for pre-2.6.32 kernels) [orabug 10286227]
- Move hwclock into udev rules
- Update oracle-enterprise.patch to fix RedHat references in arch specific
  sysctl.conf files in source tarball
- Add oracle-enterprise.patch and update specfile
- Don't attempt to re-enslave already-enslaved devices (#455537) (pknirsch@redhat.com)

[8.45.42-1]
- changed exchange_mode to 'main, aggressive' (#435274)

[8.45.41-1]
- fix check for dhcp6c pid (#568896)

[8.45.40-1]
- exit arping on first response (#744734)

[8.45.39-1]
- suppress remove error message during boot (#679998)
- fix logic error with removing arp_ip_target (#745681)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:00.222-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:14.998-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.788-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:13:34.297-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:13:34.297-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="initscripts is earlier than 0:8.45.42-1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132650"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27791" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0126 -- kvm security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0126.html" ref_id="ELSA-2010-0126"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3722" ref_id="CVE-2009-3722"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0419" ref_id="CVE-2010-0419"/>
        <description>[kvm-83-105.0.1.el5_4.27]
- Add kvm-add-oracle-workaround-for-libvirt-bug.patch

[kvm-83-105.el5_4.27]
- kvm-kernel-KVM-VMX-Check-cpl-before-emulating-debug-register-ac.patch [bz#563516]
- Resolves: bz#563516
  (KVM: Check cpl before emulating debug register access [rhel-5.4.z])

[kvm-83-105.el5_4.26]
- kvm-kernel-KVM-Don-t-check-access-permission-when-loading-segme.patch [bz#563464]
- kvm-kernel-KVM-Disable-move-to-segment-registers-and-jump-far-i.patch [bz#563464]
- Resolves: bz#563464
  (EMBARGOED CVE-2010-0419 kvm: emulator privilege escalation segment selector check [rhel-5.4.z])

[kvm-83-105.el5_4.25]
- kvm-virtio-blk-Fix-reads-turned-into-writes-after-read-e.patch [bz#562776]
- kvm-virtio-blk-Handle-bdrv_aio_read-write-NULL-return.patch [bz#562776]
- Resolves: bz#562776
  (Guest image corruption after RHEV-H update to 5.4-2.1.3.el5_4rhev2_1)

[kvm-83-105.el5_4.24]
- Apply bz#561022 patches again (undo the reverts from kvm-83-105.el5_4.23)
- kvm-qemu-add-routines-for-atomic-16-bit-accesses-take-2.patch [bz#561022]
- kvm-qemu-virtio-atomic-access-for-index-values-take-2.patch [bz#561022]
- Resolves: bz#561022
  (QEMU terminates without warning with virtio-net and SMP enabled)

[kvm-83-105.el5_4.23]
- Revert bz#561022 patches by now, until they get better testing
- kvm-Revert-qemu-virtio-atomic-access-for-index-values.patch [bz#561022]
- kvm-Revert-qemu-add-routines-for-atomic-16-bit-accesses.patch [bz#561022]
- Related: bz#561022
  (QEMU terminates without warning with virtio-net and SMP enabled)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:57.979-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:14.654-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.621-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:11:35.106-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:11:35.106-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-105.0.1.el5_4.27" test_ref="oval:org.mitre.oval:tst:134644"/>
          <criterion comment="kmod-kvm is earlier than 0:83-105.0.1.el5_4.27" test_ref="oval:org.mitre.oval:tst:135283"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-105.0.1.el5_4.27" test_ref="oval:org.mitre.oval:tst:134915"/>
          <criterion comment="kvm-tools is earlier than 0:83-105.0.1.el5_4.27" test_ref="oval:org.mitre.oval:tst:134929"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27790" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1222 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1222.html" ref_id="ELSA-2012-1222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0547" ref_id="CVE-2012-0547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1682" ref_id="CVE-2012-1682"/>
        <description>[1.6.0.0-1.28.1.10.9.0.1.el5_8]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.28.1.10.9]
- Updated to latest IcedTea6 1.10.9
- Resolves: rhbz#846709
- Resolves: rhbz#853114

[1:1.6.0.0-1.27.1.10.8]
- Access gnome bridge jar is forced to have 644 permissions
- Resolves: rhbz#828749</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:19.001-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:14.532-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.551-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:46:05.707-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:46:05.707-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.28.1.10.9.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131105"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.28.1.10.9.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131183"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.28.1.10.9.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131138"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.28.1.10.9.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131340"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.28.1.10.9.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131004"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27789" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0310 -- nfs-utils security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0310.html" ref_id="ELSA-2012-0310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1749" ref_id="CVE-2011-1749"/>
        <description>[1.0.9-60.0.1.el5]
- Add support for resvport for unmonting [orabug 13567018]

[1.0.9-60]
- Updated idmapd.conf and idmapd.conf.man to reflect the 
  static user name mapping (502707)
- Fixed an umount regression introduced by bz 513094 (bz 781931)

[1.0.9-59]
- gss: turned of even more excessive syslogs (bz 593097)
- mount.nfs: Ignored the SIGXFSZ when handling RLIMIT_FSIZE changes (bz 697979)

[1.0.9-58]
- gss: turned off more excessive syslogs (bz 593097)
- initfiles: more initscripts improvements (bz 710020)
- specfile: correct typo when nfsnobodys gid already exists (bz 729603)

[1.0.9-57]
- Mount fails to anticipate RLIMIT_FSIZE (bz 697979,CVE-2011-1749)

[1.0.9-56]
- Removed sim crash support (bz 600497)
- initfiles: more initscripts improvements (bz 710020)
- mount: Don't wait for TCP to timeout twice  (bz 736677)

[1.0.9-55]
- mount: fixed the -o retry option to retry the given amount (bz 736677)
- manpage: removed the -o fsc option (bz 715523)
- nfsstat: show v4 mounts with -m flag (bz 712438)
- mount: allow insecure ports with mounts (bz 513094)
- gss: turned off excessive syslogs (bz 593097)
- mountd: allow v2 and v3 to be disabled (bz 529588)
- specfile: make sure nfsnobodys gid changes when it exists (bz 729603)
- initfiles: initscripts improvements (bz 710020)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:14.576-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:14.419-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.497-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:02:35.568-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:02:35.568-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="nfs-utils is earlier than 0:1.0.9-60.0.1.el5" test_ref="oval:org.mitre.oval:tst:132124"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27787" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1263 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1263.html" ref_id="ELSA-2012-1263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3488" ref_id="CVE-2012-3488"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3489" ref_id="CVE-2012-3489"/>
        <description>[8.4.13-1]
- Update to PostgreSQL 8.4.13, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-13.html
  including the fixes for CVE-2012-3488, CVE-2012-3489
Resolves: #852020</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:34.330-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:14.122-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.216-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:21:00.109-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:21:00.109-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130478"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131259"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131028"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131032"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130428"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131193"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131002"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130747"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131149"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130351"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131064"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131131"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131310"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131217"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131218"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131039"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:130959"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131349"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:130708"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:130961"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131045"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131350"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27786" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0307 -- util-linux security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>util-linux</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0307.html" ref_id="ELSA-2012-0307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1675" ref_id="CVE-2011-1675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1677" ref_id="CVE-2011-1677"/>
        <description>[2.13-0.59.0.1.el5]
- Merge UEK modification
  fix #10104470 - Import hwclock from util-linux-ng [Kris Van Hees]

[2.13-0.59]
- fix #768382 - CVE-2011-1675 CVE-2011-1677 util-linux various flaws

[2.13-0.58]
- fix #677452 - util-linux fails to build with gettext-0.17

[2.13-0.57]
- fix #646300 - login doesn't update /var/run/utmp properly
- fix #726572 - import missing fsfreeze into util-linux 
- fix #678430 - fdisk should not report error on 1gB LUNs
- fix #699639 - mount man page is missing support for ext4/xfs
- fix #650937 - blockdev man page missing information
- fix #678407 - ipcs and ipcrm in wrong man section</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:23.722-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:13.786-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.064-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:29:20.068-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:29:20.068-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="util-linux is earlier than 0:2.13-0.59.0.1.el5" test_ref="oval:org.mitre.oval:tst:132562"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27785" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0978 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0978.html" ref_id="ELSA-2010-0978"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4180" ref_id="CVE-2010-4180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7270" ref_id="CVE-2008-7270"/>
        <description>[0.9.8e-12.7]
- fix CVE-2010-4180 - completely disable code for
  SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG (#659462)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:55.502-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:13.435-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:56.933-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:10:43.064-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:10:43.064-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_5.7" test_ref="oval:org.mitre.oval:tst:134675"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_5.7" test_ref="oval:org.mitre.oval:tst:134649"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_5.7" test_ref="oval:org.mitre.oval:tst:134426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27781" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1212 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1212.html" ref_id="ELSA-2011-1212"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2482" ref_id="CVE-2011-2482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2491" ref_id="CVE-2011-2491"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2495" ref_id="CVE-2011-2495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2517" ref_id="CVE-2011-2517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2519" ref_id="CVE-2011-2519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2901" ref_id="CVE-2011-2901"/>
        <description>[2.6.18-274.3.1.0.1.el5]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- fix missing aio_complete() in end_io (Joel Becker) [orabug 10365195]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:17.035-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:12.242-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:56.397-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:41:04.863-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:41:04.863-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133293"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.3.1.0.1.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:132572"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.3.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133151"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132850"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133528"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133423"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133413"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132810"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133205"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133385"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133403"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133474"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.3.1.0.1.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:132874"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.3.1.0.1.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:132603"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.3.1.0.1.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133265"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.3.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133584"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.3.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132983"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.3.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133390"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27778" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2039 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2039.html" ref_id="ELSA-2012-2039"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.39-200.33.1]

- sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE (Ben Hutchings) [Orabug: 14769994]

- CVE-2012-3412 sfc: Fix maximum number of TSO segments and minimum TX queue size (Ben Hutchings) [Orabug: 14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:52.476-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:11.743-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:56.119-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130673"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130762"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:131014"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130863"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130861"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130956"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130922"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130882"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130526"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130550"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130797"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27777" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0475 -- sudo security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0475.html" ref_id="ELSA-2010-0475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1646" ref_id="CVE-2010-1646"/>
        <description>[1.7.2p1-7]
- added patch that fixes insufficient environment sanitization issue (#598154)
  Resolves: #598381</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:08.283-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:11.472-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.987-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:44:12.737-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:44:12.737-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-7.el5_5" test_ref="oval:org.mitre.oval:tst:135122"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27775" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1959-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1959-1.html" ref_id="ELSA-2014-1959-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0181" ref_id="CVE-2014-0181"/>
        <description>kernel [2.6.18-400.0.0.0.1] - [net] fix tcp_trim_head() (James Li) [orabug
          14512145, 19219078] - ocfs2: dlm: fix recovery hung (Junxiao Bi) [orabug 13956772] - i386:
          fix MTRR code (Zhenzhong Duan) [orabug 15862649] - [oprofile] x86, mm: Add
          __get_user_pages_fast() [orabug 14277030] - [oprofile] export __get_user_pages_fast()
          function [orabug 14277030] - [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support
          [orabug 14277030] - [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
          - [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030] - [kernel]
          Initialize the local uninitialized variable stats. [orabug 14051367] - [fs] JBD:make jbd
          support 512B blocks correctly for ocfs2. [orabug 13477763] - [x86 ] fix fpu context
          corrupt when preempt in signal context [orabug 14038272] - [mm] fix hugetlb page leak
          (Dave McCracken) [orabug 12375075] - fix ia64 build error due to
          add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use dynamic vcpu_info remap to
          support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0 reset when hvm boot up with
          noapic param - [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris
          Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin)
          [orabug 12561346] - [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
          - [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
          - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646] -
          fix filp_close() race (Joe Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default
          [orabug 67188919] - [xen] check to see if hypervisor supports memory reservation change
          (Chuck Anderson) [orabug 7556514] - [net] Enable entropy for
          bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki) [orabug 10315433] - [NET] Add xen
          pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258] - [mm] Patch shrink_zone to
          yield during severe mempressure events, avoiding hangs and evictions (John Sobecki,Chris
          Mason) [orabug 6086839] - [mm] Enhance shrink_zone patch allow full swap utilization, and
          also be NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919] - fix
          aacraid not to reset during kexec (Joe Jin) [orabug 8516042] - [xen] PVHVM guest with PoD
          crashes under memory pressure (Chuck Anderson) [orabug 9107465] - [xen] PV guest with FC
          HBA hangs during shutdown (Chuck Anderson) [orabug 9764220] - Support 256GB+ memory for pv
          guest (Mukesh Rathor) [orabug 9450615] - fix overcommit memory to use percpu_counter for
          (KOSAKI Motohiro, Guru Anbalagane) [orabug 6124033] - [ipmi] make configurable timeouts
          for kcs of ipmi [orabug 9752208] - [ib] fix memory corruption (Andy Grover) [orabug
          9972346] - [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug
          14795203] - [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug
          14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:23.511-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:14.813-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:15.490-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37623 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:36.055-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:32.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135627"/>
          <criterion comment="ocfs2-2.6.18-400.0.0.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135654"/>
          <criterion comment="oracleasm-2.6.18-400.0.0.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135787"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135345"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135778"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135195"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135151"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135789"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135666"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135434"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135820"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-400.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:135886"/>
          <criterion comment="ocfs2-2.6.18-400.0.0.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135790"/>
          <criterion comment="ocfs2-2.6.18-400.0.0.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135720"/>
          <criterion comment="ocfs2-2.6.18-400.0.0.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:135762"/>
          <criterion comment="oracleasm-2.6.18-400.0.0.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135909"/>
          <criterion comment="oracleasm-2.6.18-400.0.0.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134964"/>
          <criterion comment="oracleasm-2.6.18-400.0.0.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134990"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27771" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1413 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1413.html" ref_id="ELSA-2012-1413"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4194" ref_id="CVE-2012-4194"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4195" ref_id="CVE-2012-4195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4196" ref_id="CVE-2012-4196"/>
        <description>[10.0.10-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[10.0.10-1]
- Update to 10.0.10 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:32.784-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:10.287-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.501-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:06:34.119-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:06:34.119-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130929"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27767" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0322 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0322.html" ref_id="ELSA-2012-0322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3563" ref_id="CVE-2011-3563"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0497" ref_id="CVE-2012-0497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0501" ref_id="CVE-2012-0501"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0502" ref_id="CVE-2012-0502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0503" ref_id="CVE-2012-0503"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0505" ref_id="CVE-2012-0505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0506" ref_id="CVE-2012-0506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3571" ref_id="CVE-2011-3571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5035" ref_id="CVE-2011-5035"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507" ref_id="CVE-2012-0507"/>
        <description>[1.6.0.0-1.25.1.10.6.0.1.el5_8]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.25.1.10.6]
- Updated to IcedTea6 1.10.6
- Resolves: rhbz#787142
- Security fixes
  - S7082299: Fix in AtomicReferenceArray
  - S7088367: Fix issues in java sound
  - S7110683: Issues with some KeyboardFocusManager method
  - S7110687: Issues with TimeZone class
  - S7110700: Enhance exception throwing mechanism in ObjectStreamClass
  - S7110704: Issues with some method in corba
  - S7112642: Incorrect checking for graphics rendering object
  - S7118283: Better input parameter checking in zip file processing
  - S7126960: Add property to limit number of request headers to the HTTP Server
- Bug fixes
  - RH580478: Desktop files should not use hardcoded path
- Removed and deleted upstreamed  patch7 - name-rmi-fix.patch
- Removed and deleted upstreamed Hugepages patches:
  - Source100: 7034464-hugepage.patch
  - Source101: 7037939-hugepage.patch
  - Source102: 7043564-hugepage.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:25.898-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:08.824-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.009-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:43:08.998-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:43:08.998-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.25.1.10.6.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131788"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.25.1.10.6.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132425"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.25.1.10.6.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132596"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.25.1.10.6.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131854"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.25.1.10.6.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132682"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27763" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0894 -- systemtap security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0894.html" ref_id="ELSA-2010-0894"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4170" ref_id="CVE-2010-4170"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4171" ref_id="CVE-2010-4171"/>
        <description>[1.2-11.0.1.el6_0]

- rebuild without docs

- remove doc/SystemTap_Beginners_Guide/en-US in tarball



[1.2-11]

- CVE-2010-4170

- CVE-2010-4171</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:43.150-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:07.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.557-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:02:11.263-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:02:11.263-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134754"/>
            <criterion comment="systemtap-client is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:133964"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134809"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134262"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134587"/>
            <criterion comment="systemtap-server is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134376"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134768"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134780"/>
            <criterion comment="systemtap-client is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134629"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134861"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134738"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134805"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134850"/>
            <criterion comment="systemtap-server is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134866"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134822"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27762" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0547 -- php53 security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0547.html" ref_id="ELSA-2012-0547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1823" ref_id="CVE-2012-1823"/>
        <description>[5.3.3-7]
- correct detection of = in CVE-2012-1823 fix (#818607)

[5.3.3-6]
- add security fix for CVE-2012-1823 (#818607)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:25.088-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:07.609-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.417-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:21:01.875-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:21:01.875-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php53 is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132159"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132189"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132209"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:131829"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132284"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132221"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:131383"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132222"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132279"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132215"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132242"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132114"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132173"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:131941"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132145"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:131653"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:131339"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132314"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:131401"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132328"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-7.el5_8" test_ref="oval:org.mitre.oval:tst:132383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27761" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1288 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1288.html" ref_id="ELSA-2012-1288"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3102" ref_id="CVE-2011-3102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2807" ref_id="CVE-2012-2807"/>
        <description>[2.7.6-8.0.1.el6_3.3 ]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-8.el6_3.3]
- Change the XPath code to percolate allocation error (CVE-2011-1944)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:33.673-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:07.188-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.284-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:13:43.045-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:13:43.045-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131188"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130725"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130438"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130968"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131078"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131166"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130770"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27760" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0019 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0019.html" ref_id="ELSA-2012-0019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4566" ref_id="CVE-2011-4566"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4885" ref_id="CVE-2011-4885"/>
        <description>[5.3.3-3.5]
- remove extra php.ini-prod/devel files caused by %patch -b

[5.3.3-3.4]
- add security fixes for CVE-2011-4885, CVE-2011-4566 (#769754)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:10.184-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:06.881-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.088-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:14:48.333-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:14:48.333-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132592"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132913"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132678"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132354"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132890"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132243"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132739"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132256"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132733"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132609"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132791"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132721"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132553"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132875"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132019"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132685"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132576"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132045"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132713"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132310"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132866"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133004"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132593"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132886"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132655"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132988"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132048"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132905"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132444"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133026"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133003"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132072"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132724"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132776"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132821"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132743"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132802"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132965"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132697"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132760"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132878"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132993"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132997"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132949"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132290"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133011"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132774"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27752" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1181 -- gimp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1181.html" ref_id="ELSA-2012-1181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3909" ref_id="CVE-2009-3909"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3402" ref_id="CVE-2012-3402"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3403" ref_id="CVE-2012-3403"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3481" ref_id="CVE-2012-3481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2896" ref_id="CVE-2011-2896"/>
        <description>[2:2.2.13-2.0.7.el5_8.5]
- fix overflow in GIF loader (CVE-2012-3481)

[2:2.2.13-2.0.7.el5_8.4]
- fix overflows in PSD plugin (CVE-2009-3909, CVE-2012-3402)
- fix heap corruption and overflow in GIF plug-in (CVE-2011-2896)
- fix overflow in CEL plug-in (CVE-2012-3403)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:24.242-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:02.645-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:52.052-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:58:26.663-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:58:26.663-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gimp is earlier than 0:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:130825"/>
          <criterion comment="gimp-devel is earlier than 0:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:131272"/>
          <criterion comment="gimp-libs is earlier than 0:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:131137"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27751" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0332 -- scsi-target-utils security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0332.html" ref_id="ELSA-2011-0332"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0001" ref_id="CVE-2011-0001"/>
        <description>[1.0.4-3.1]
- fix the buffer overflow bug before iscsi login (CVE-2011-0001)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:57.078-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:02.429-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:51.936-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:56:45.722-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:56:45.722-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="scsi-target-utils is earlier than 0:1.0.8-0.el5_6.1" test_ref="oval:org.mitre.oval:tst:133751"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="scsi-target-utils is earlier than 0:1.0.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134176"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27748" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0162 -- openssl security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0162.html" ref_id="ELSA-2010-0162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0433" ref_id="CVE-2010-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3245" ref_id="CVE-2009-3245"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" ref_id="CVE-2009-3555"/>
        <description>[0.9.8e-12.6]
- fix CVE-2009-3245 - add missing bn_wexpand return checks (#570924)

[0.9.8e-12.5]
- fix CVE-2010-0433 - do not pass NULL princ to krb5_kt_get_entry which
  in the RHEL-5 and newer versions will crash in such case (#569774)

[0.9.8e-12.4]
- do not disable SSLv2 in the renegotiation patch - SSLv2 does
  not support renegotiation
- allow unsafe renegotiation on clients with SSL_OP_LEGACY_SERVER_CONNECT

[0.9.8e-12.3]
- mention the RFC5746 in the CVE-2009-3555 doc

[0.9.8e-12.2]
- fix CVE-2009-3555 - support the safe renegotiation extension and
  do not allow legacy renegotiation on the server by default (#533125)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:49.342-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:01.092-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:51.141-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:24:25.951-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:24:25.951-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:134773"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:135228"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:135263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27747" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0028 -- kvm security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0028.html" ref_id="ELSA-2011-0028"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4525" ref_id="CVE-2010-4525"/>
        <description>A data structure field in kvm_vcpu_ioctl_x86_get_vcpu_events() in QEMU-KVM
was not initialized properly before being copied to user-space. A
privileged host user with access to "/dev/kvm" could use this flaw to leak
kernel stack memory to user-space.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:06.552-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:00.830-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:50.935-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:25:59.230-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:25:59.230-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-224.0.1.el5" test_ref="oval:org.mitre.oval:tst:134470"/>
          <criterion comment="kmod-kvm is earlier than 0:83-224.0.1.el5" test_ref="oval:org.mitre.oval:tst:134676"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-224.0.1.el5" test_ref="oval:org.mitre.oval:tst:134728"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-224.0.1.el5" test_ref="oval:org.mitre.oval:tst:134606"/>
          <criterion comment="kvm-tools is earlier than 0:83-224.0.1.el5" test_ref="oval:org.mitre.oval:tst:134697"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27746" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2043 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2043.html" ref_id="ELSA-2012-2043"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2133" ref_id="CVE-2012-2133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3400" ref_id="CVE-2012-3400"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3511" ref_id="CVE-2012-3511"/>
        <description>[2.6.39-300.17.2]

- hugepages: fix use after free bug in 'quota' handling [Orabug: 15845276] {CVE-2012-2133}

- udf: Fortify loading of sparing table [Orabug: 15845302] {CVE-2012-3400}

- udf: Avoid run away loop when partition table length is corrupt [Orabug: 15845302] {CVE-2012-3400}

- mm: Hold a file reference in madvise_remove [Orabug: 15846025] {CVE-2012-3511}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:35.299-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:00.629-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:50.776-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130837"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130821"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130924"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129995"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130529"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129988"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130693"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130986"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130904"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130627"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130935"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130969"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27745" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0426 -- openssl security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0426.html" ref_id="ELSA-2012-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0884" ref_id="CVE-2012-0884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1165" ref_id="CVE-2012-1165"/>
        <description>[1.0.0-20.3]

- fix problem with the SGC restart patch that might terminate handshake

  incorrectly

- fix for CVE-2012-0884 - MMA weakness in CMS and PKCS#7 code (#802725)

- fix for CVE-2012-1165 - NULL read dereference on bad MIME headers (#802489)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:17.279-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:00.298-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:50.629-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:01:33.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:01:33.577-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:132481"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:132426"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:132361"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132571"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132351"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132353"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132226"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27744" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1445 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1445.html" ref_id="ELSA-2012-1445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2100" ref_id="CVE-2012-2100"/>
        <description>[2.6.18-308.20.1.el5]
- Revert: [x86] mm: randomize SHLIB_BASE (Dave Anderson) [804953 804954] {CVE-2012-1568}

[2.6.18-308.19.1.el5]
- [net] be2net: Remove code that stops further access to BE NIC based on UE bits (Alexander Gordeev) [867896 862811]
- [net] netpoll: fix an incorrect check for NULL pointer (Alexander Gordeev) [856079 848098]
- [net] mlx4: Add support for EEH error recovery (Alexander Gordeev) [847404 798048]
- [fs] ext4: fix undefined bit shift result in ext4_fill_flex_info (Eric Sandeen) [809688 809689] {CVE-2012-2100}
- [fs] ext4: fix undefined behavior in ext4_fill_flex_info (Eric Sandeen) [809688 809689] {CVE-2012-2100}
- [fs] fix crash if block {device|size} read &amp; changed at sametime (Mikulas Patocka) [864823 756506]
- [x86] mm: randomize SHLIB_BASE (Dave Anderson) [804953 804954] {CVE-2012-1568}
- [net] ipv6: Fix fib6_dump_table walker leak (Jiri Benc) [861387 819830]
- [fs] cifs: update cifs_dfs_d_automount caller path (Sachin Prabhu) [858774 857448]
- [xen] x86: change the default behaviour of CVE-2012-2934 fix (Petr Matousek) [859946 858724]
- [net] ipvs: allow transmit of GRO aggregated skbs (Jesper Brouer) [857966 854067]
- [scsi] isci: fixup linkspeed definitions (David Milburn) [854986 833000]
- [fs] nfs: nfs_d_automount update caller path after do_add_mount (Carlos Maiolino) [857552 834379]
- [fs] vfs: Fix vfsmount overput on simultaneous automount (Carlos Maiolino) [857552 834379]

[2.6.18-308.18.1.el5]
- [fs] autofs4: Merge the remaining dentry ops tables (Ian Kent) [857558 850977]

[2.6.18-308.17.1.el5]
- [fs] cifs: Invalidate file cache in case of posix open (Sachin Prabhu) [857964 852526]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:41.191-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:00.118-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:50.492-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:07:26.333-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:07:26.333-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130460"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.20.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130735"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.20.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130887"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130479"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130769"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130756"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130147"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130874"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130514"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130469"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130373"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.20.1.el5" test_ref="oval:org.mitre.oval:tst:130878"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.20.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130731"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.20.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130678"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.20.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130603"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.20.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129960"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.20.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130715"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.20.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130857"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27741" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1479 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1479.html" ref_id="ELSA-2011-1479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1162" ref_id="CVE-2011-1162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1898" ref_id="CVE-2011-1898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2203" ref_id="CVE-2011-2203"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2494" ref_id="CVE-2011-2494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3363" ref_id="CVE-2011-3363"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4110" ref_id="CVE-2011-4110"/>
        <description>kernel
[2.6.18-274.12.1.0.1.el5]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [scsi] add additional scsi medium error handling (John Sobecki) [orabug 12904887]
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- bonding: reread information about speed and duplex when interface goes up (John Haxby) [orabug 11890822]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [aio] patch removes limit on number of retries (Srinivas Eeda) [orabug 10044782]
- [loop] Do not call loop_unplug for not configured loop device (orabug 10314497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:22.513-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:59.302-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:50.144-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:14:47.058-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:14:47.058-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133169"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.12.1.0.1.el5-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:133074"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.12.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133224"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132960"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132666"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133162"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133155"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133050"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133056"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133209"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133199"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:133186"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.12.1.0.1.el5PAE-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132595"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.12.1.0.1.el5debug-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132823"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.12.1.0.1.el5xen-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:133038"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.12.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133212"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.12.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133136"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.12.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133013"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27739" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1255 -- libexif security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libexif</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1255.html" ref_id="ELSA-2012-1255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2812" ref_id="CVE-2012-2812"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2813" ref_id="CVE-2012-2813"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2814" ref_id="CVE-2012-2814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2836" ref_id="CVE-2012-2836"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2837" ref_id="CVE-2012-2837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2840" ref_id="CVE-2012-2840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2841" ref_id="CVE-2012-2841"/>
        <description>[0.6.21-5]
- Update to version 0.6.21 fixing many bugs and CVEs
- Remove upstreamed patches
- Resolves: #839915</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:20.346-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:55.940-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:48.856-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:05:29.550-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:05:29.550-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libexif is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:131242"/>
            <criterion comment="libexif-devel is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:131345"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libexif is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:131214"/>
            <criterion comment="libexif-devel is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:130926"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27738" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1948 -- nss, nss-util, and nss-softokn security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1948.html" ref_id="ELSA-2014-1948"/>
        <description>[3.16.2.3-2.0.1.el7_0]
- Added nss-vendor.patch to change vendor

[3.16.2.3-2]
- Restore patch for certutil man page
- supply missing options descriptions
- Resolves: Bug 1165525 - Upgrade to NSS 3.16.2.3 for Firefox 31.3</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:31.805-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:13.578-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:14.373-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136045"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136044"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135871"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135923"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135884"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135903"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135849"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135800"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135863"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:136041"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135475"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135518"/>
            <criterion comment="nss-softokn is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135943"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135336"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135683"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135765"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135292"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135697"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136043"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135919"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135947"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136002"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27737" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0839 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0839.html" ref_id="ELSA-2010-0839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3477" ref_id="CVE-2010-3477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3066" ref_id="CVE-2010-3066"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3067" ref_id="CVE-2010-3067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3078" ref_id="CVE-2010-3078"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3086" ref_id="CVE-2010-3086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3448" ref_id="CVE-2010-3448"/>
        <description>[2.6.18-194.26.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) 
  [orabug 9504524]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)
  [orabug 9245919]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:00.257-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:55.147-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:48.530-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:52:42.107-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:52:42.107-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134191"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.26.1.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134824"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.26.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134835"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134670"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134196"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134825"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134787"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134332"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134709"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134896"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134628"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.26.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134437"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.26.1.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134698"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.26.1.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134715"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.26.1.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134857"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.26.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134453"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.26.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134384"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.26.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134616"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27735" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2026 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2026.html" ref_id="ELSA-2012-2026"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083" ref_id="CVE-2011-1083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2745" ref_id="CVE-2012-2745"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3375" ref_id="CVE-2012-3375"/>
        <description>[2.6.32-300.29.2] - epoll: epoll_wait() should not use timespec_add_ns() (Eric
          Dumazet) - epoll: clear the tfile_check_list on -ELOOP (Joe Jin) {CVE-2012-3375} - Don't
          limit non-nested epoll paths (Jason Baron) - epoll: kabi fixups for epoll limit wakeup
          paths (Joe Jin) {CVE-2011-1083} - epoll: limit paths (Jason Baron) {CVE-2011-1083} -
          eventpoll: fix comment typo 'evenpoll' (Paul Bolle) - epoll: fix compiler warning and
          optimize the non-blocking path (Shawn Bohrer) - epoll: move ready event check into proper
          inline (Davide Libenzi) - epoll: make epoll_wait() use the hrtimer range feature (Shawn
          Bohrer) - select: rename estimate_accuracy() to select_estimate_accuracy() (Andrew Morton)
          - cred: copy_process() should clear child->replacement_session_keyring (Oleg Nesterov)
          {CVE-2012-2745}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:37.842-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:54.689-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:48.200-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130681 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:41.770-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:32.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131605"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131448"/>
            <criterion comment="ofa-2.6.32-300.29.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131598"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131613"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131264"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131583"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131215"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131509"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131489"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130681"/>
            <criterion comment="ofa-2.6.32-300.29.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131453"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:130732"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131578"/>
            <criterion comment="ofa-2.6.32-300.29.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131478"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:130987"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131375"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131608"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131246"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131326"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131611"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131572"/>
            <criterion comment="ofa-2.6.32-300.29.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131569"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27731" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0198 -- postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0198.html" ref_id="ELSA-2011-0198"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4015" ref_id="CVE-2010-4015"/>
        <description>[8.4.7-1.el5_6.1]
- Update to PostgreSQL 8.4.7, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-7.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-6.html
  including the fix for CVE-2010-4015
Resolves: #672636
- Ensure we don't package any .gitignore files from the source tarball</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:04.088-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:53.860-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:47.678-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:51:29.142-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:51:29.142-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql84 is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134155"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134260"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134707"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134395"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134692"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134484"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:133749"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134558"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:133945"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134681"/>
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134632"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:134053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27730" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0721 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0721.html" ref_id="ELSA-2012-0721"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0217" ref_id="CVE-2012-0217"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2934" ref_id="CVE-2012-2934"/>
        <description>kernel:

[2.6.18-308.8.2.el5]
- [xen] x86_64: check address on trap handlers or guest callbacks (Paolo Bonzini) [813430 813431] {CVE-2012-0217}
- [xen] x86_64: Do not execute sysret with a non-canonical return address (Paolo Bonzini) [813430 813431] {CVE-2012-0217}
- [xen] x86: prevent hv boot on AMD CPUs with Erratum 121 (Laszlo Ersek) [824969 824970]

ocfs2:

[1.4.10]
- ocfs2/dlm: Cleanup mlogs in dlmthread.c dlmast.c and dlmdomain.c
- ocfs2/dlm: make existing convertion precedent over new lock
- ocfs2/dlm: Cleanup dlmdebug.c
- ocfs2/dlm: Minor cleanup
- ocfs2/dlm: Hard code the values for enums
- ocfs2: Wakeup down convert thread just after clearing OCFS2 LOCK UPCONVERT FINISHING
- ocfs2/dlm: Take inflight reference count for remotely mastered resources too
- ocfs2/dlm: dlmlock remote needs to account for remastery
- ocfs2: Add some trace log for orphan scan
- ocfs2: Remove unused old id in ocfs2_commit_cache
- ocfs2: Remove obsolete comments before ocfs2_start_trans
- ocfs2: Initialize the bktcnt variable properly and call it bucket_count
- ocfs2: Use cpu to le16 for e leaf clusters in ocfs2_bg_discontig_add_extent
- ocfs2: validate bg free bits count after update
- ocfs2: cluster Pin the remote node item in configfs
- ocfs2: Release buffer head in case of error in ocfs2_double_lock
- ocfs2: optimize ocfs2 check dir entry with unlikely() annotations
- ocfs2: Little refactoring against ocfs2 iget
- ocfs2: Initialize data ac might be used uninitializ
- ocfs2 Skip mount recovery for hard ro mounts
- ocfs2: make direntry invalid when deleting it
- ocfs2: commit trans in error
- ocfs2: Fix deadlock when allocating page
- ocfs2: Avoid livelock in ocfs2 readpage</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:22.225-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:53.600-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:47.522-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:17:37.170-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:17:37.170-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131938"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.2.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131807"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.2.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131796"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131905"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131660"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131704"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131760"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131876"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131900"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131833"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131499"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.8.2.el5" test_ref="oval:org.mitre.oval:tst:131397"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.2.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131932"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.2.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131541"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.2.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:132006"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.2.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131858"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.2.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131930"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.2.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131443"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27729" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0308 -- busybox security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>busybox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0308.html" ref_id="ELSA-2012-0308"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2716" ref_id="CVE-2011-2716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1168" ref_id="CVE-2006-1168"/>
        <description>[1:1.2.0-13]
- Resolves: #768083 'busybox various flaws' including:
  'buffer underflow in decompression'
  'udhcpc insufficient checking of DHCP options'

[1:1.2.0-12]
- Resolves: #756723
  'Kdump fails after findfs subcommand of busybox fails'

[1:1.2.0-11]
- Resolves: #689659
  ''busybox cp' does not return a correct exit code when 'No space left on device''</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:13.731-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:53.382-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:47.357-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:25:22.455-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:25:22.455-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="busybox is earlier than 0:1.2.0-13.el5" test_ref="oval:org.mitre.oval:tst:132388"/>
          <criterion comment="busybox-anaconda is earlier than 0:1.2.0-13.el5" test_ref="oval:org.mitre.oval:tst:132616"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27727" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1256 -- ghostscript security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1256.html" ref_id="ELSA-2012-1256"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4405" ref_id="CVE-2012-4405"/>
        <description>[8.70-14:.1]
- Added inputChan lower-bounds checking to icclib (bug #854227,
  CVE-2012-4405).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:16.281-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:53.186-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:47.192-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:06:04.288-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:06:04.288-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:131325"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:131199"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:131226"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130691"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130899"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:131148"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130722"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27726" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0060 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0060.html" ref_id="ELSA-2012-0060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4108" ref_id="CVE-2011-4108"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4109" ref_id="CVE-2011-4109"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4576" ref_id="CVE-2011-4576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4619" ref_id="CVE-2011-4619"/>
        <description>[0.9.8e-20.1]
- fix for CVE-2011-4108 &amp; CVE-2012-0050 - DTLS plaintext recovery
  vulnerability and additional DTLS fixes (#771770)
- fix for CVE-2011-4109 - double free in policy checks (#771771)
- fix for CVE-2011-4576 - uninitialized SSL 3.0 padding (#771775)
- fix for CVE-2011-4619 - SGC restart DoS attack (#771780)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:29.351-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:52.789-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:46.949-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:59:56.008-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:59:56.008-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:132035"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:132622"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:132865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27723" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0825 -- mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0825.html" ref_id="ELSA-2010-0825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3677" ref_id="CVE-2010-3677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3680" ref_id="CVE-2010-3680"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3681" ref_id="CVE-2010-3681"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3682" ref_id="CVE-2010-3682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3833" ref_id="CVE-2010-3833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3835" ref_id="CVE-2010-3835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3836" ref_id="CVE-2010-3836"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3837" ref_id="CVE-2010-3837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3838" ref_id="CVE-2010-3838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3839" ref_id="CVE-2010-3839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3840" ref_id="CVE-2010-3840"/>
        <description>[5.0.77-4.4]

- Add fixes for CVE-2010-3677, CVE-2010-3680, CVE-2010-3681, CVE-2010-3682,

  CVE-2010-3833, CVE-2010-3835, CVE-2010-3836, CVE-2010-3837, CVE-2010-3838,

  CVE-2010-3839, CVE-2010-3840

Resolves: #645642

- Backpatch strmov fix so that code can be tested on more recent platforms</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:48.952-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:51.351-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:46.298-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:11:51.072-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:11:51.072-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:134380"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:134321"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:134633"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:134819"/>
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:134721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27722" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1207 -- glibc security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1207.html" ref_id="ELSA-2012-1207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3480" ref_id="CVE-2012-3480"/>
        <description>[2.5-81.el5_8.7]
- Fix out of bounds array access in strto* exposed by 847929 patch.

[2.5-81.el5_8.6]
- Fix integer overflow leading to buffer overflow in strto* (#847929)

[2.5-81.el5_8.5]
- Do not use PT_IEEE_IP ptrace calls (#839411)
- Update ULPs (#839411)
- Fix various transcendentals in non-default rounding modes (#839411)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:31.199-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:51.174-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:46.207-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:53:26.588-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:53:26.588-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:130632"/>
          <criterion comment="glibc-common is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:131304"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:130960"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:130604"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:131332"/>
          <criterion comment="nscd is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:130456"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27720" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1065 -- Oracle Linux 5.7 kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1065.html" ref_id="ELSA-2011-1065"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1780" ref_id="CVE-2011-1780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2525" ref_id="CVE-2011-2525"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2689" ref_id="CVE-2011-2689"/>
        <description>[2.6.18-274.el5]
- [xen] svm: fix invlpg emulator regression (Paolo Bonzini) [719894]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:39.482-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:50.555-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:45.760-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:23:19.921-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:23:19.921-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:132927"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.el5-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133221"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133373"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133634"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133577"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133058"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133530"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133128"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133485"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133611"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133506"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.el5" test_ref="oval:org.mitre.oval:tst:133478"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.el5PAE-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133499"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.el5debug-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133509"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.el5xen-1.4.8-2.el5" test_ref="oval:org.mitre.oval:tst:133036"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:133512"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132719"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132970"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27718" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1037 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1037.html" ref_id="ELSA-2012-1037"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2143" ref_id="CVE-2012-2143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2655" ref_id="CVE-2012-2655"/>
        <description>[8.4.12-1]
- Update to PostgreSQL 8.4.12, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-12.html
  including the fixes for CVE-2012-2143, CVE-2012-2655
Resolves: #830723

[8.4.11-2]
- Add patches for CVE-2012-2143, CVE-2012-2655
Resolves: #830723

[8.4.11-1]
- Update to PostgreSQL 8.4.11, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-10.html
  including the fixes for CVE-2012-0866, CVE-2012-0867, CVE-2012-0868
Resolves: #812077</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:32.197-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:50.270-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:45.503-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:01:54.008-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:01:54.008-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131842"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131856"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131552"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131236"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131492"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131830"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131855"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:130981"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131641"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131752"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131560"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131721"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131835"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131706"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131525"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131790"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:130912"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:130943"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131672"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131844"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131513"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131859"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27717" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0496 -- xen security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0496.html" ref_id="ELSA-2011-0496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1583" ref_id="CVE-2011-1583"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3262" ref_id="CVE-2011-3262"/>
        <description>[3.0.3-120.el5_6.2]
- Fix logic and integer overflow in xc_try_bzip2_decode() (rhbz 696938)
- Fix logic and integer overflow in xc_try_lzma_decode() (rhbz 696938)
- Fix integer and buffer overflows in xc_dom_probe_bzimage_kernel() (rhbz 696938)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:52.339-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:49.956-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:45.222-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:13:34.112-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:13:34.112-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xen is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:133821"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:133815"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:134093"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27715" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0546 -- php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0546.html" ref_id="ELSA-2012-0546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1823" ref_id="CVE-2012-1823"/>
        <description>[5.3.3-3.8]
- correct detection of = in CVE-2012-1823 fix (#818607)

[5.3.3-3.7]
- add security fix for CVE-2012-1823 (#818607)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:05.294-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:49.451-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:44.892-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:25:10.626-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:25:10.626-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132336"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132308"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132365"/>
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132390"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132141"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132357"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132229"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132107"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:131419"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132292"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132252"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132324"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132228"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132076"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132199"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132331"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132348"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132342"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132257"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132406"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132084"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132073"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132219"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132238"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132297"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131919"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132317"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131638"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131956"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131942"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132277"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132165"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132374"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132281"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132211"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132352"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132286"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132146"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132067"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132405"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132177"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132196"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132246"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132276"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132204"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27713" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1267 -- bind security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1267.html" ref_id="ELSA-2012-1267"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244" ref_id="CVE-2012-4244"/>
        <description>[30:9.3.6-20.P1.4]
- bind-chroot-admin: set correct permissions on /etc/named.conf during update

[30:9.3.6-20.P1.3]
- fix CVE-2012-4244</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:36.670-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:48.360-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:44.252-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:24:12.062-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:24:12.062-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:130703"/>
          <criterion comment="bind-chroot is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:130868"/>
          <criterion comment="bind-devel is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:131230"/>
          <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:130916"/>
          <criterion comment="bind-libs is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:130244"/>
          <criterion comment="bind-sdb is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:130849"/>
          <criterion comment="bind-utils is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:131145"/>
          <criterion comment="caching-nameserver is earlier than 0:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:130745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27711" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1824 -- php security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1824.html" ref_id="ELSA-2014-1824"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3669" ref_id="CVE-2014-3669"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3670" ref_id="CVE-2014-3670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8626" ref_id="CVE-2014-8626"/>
        <description>[5.1.6-45]
- core: fix integer overflow in unserialize() CVE-2014-3669
- exif: fix heap corruption issue in exif_thumbnail() CVE-2014-3670
- xmlrpc: fix buffer overflow in date parser #1155607</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:47.179-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:47.953-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:15.672-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135066"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135769"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135722"/>
          <criterion comment="php-common is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135560"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135520"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135264"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135700"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135756"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135766"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135028"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135638"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135676"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135753"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135588"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135717"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135598"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135744"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135505"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-45.el5_11" test_ref="oval:org.mitre.oval:tst:135752"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27705" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0311 -- ibutils security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ibutils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0311.html" ref_id="ELSA-2012-0311"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3277" ref_id="CVE-2008-3277"/>
        <description>[1.2-11.2.0.1.el5]
- Fix double malloc and free problem in CrdLoopPrepare and CrdLoopCleanup

[1.2-11.2.el5]
- Added Requires lines for ibutils-libs to make rpmdiff happier.
- Add patch for CVE-2008-3277
  Resolves: bz768400

[1.2-11.1.el5]
- Add ibutils-1.2-invalid-delete.patch to close
  Resolves: bz711779</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:08.775-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:44.052-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:42.108-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:49:47.098-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:49:47.098-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ibutils is earlier than 0:1.2-11.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131981"/>
          <criterion comment="ibutils-devel is earlier than 0:1.2-11.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:132664"/>
          <criterion comment="ibutils-libs is earlier than 0:1.2-11.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:132692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27702" version="5" class="patch">
      <metadata>
        <title>ELSA-2010-2011 -- Unbreakable enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-firmware</product>
          <product>kernel-headers</product>
          <product>ofa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-2011.html" ref_id="ELSA-2010-2011"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3432" ref_id="CVE-2010-3432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3437" ref_id="CVE-2010-3437"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3442" ref_id="CVE-2010-3442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3698" ref_id="CVE-2010-3698"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3705" ref_id="CVE-2010-3705"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2955" ref_id="CVE-2010-2955"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2962" ref_id="CVE-2010-2962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3079" ref_id="CVE-2010-3079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3084" ref_id="CVE-2010-3084"/>
        <description>Following Security fixes are included in this unbreakable enterprise kernel
          errata: CVE-2010-3432 The sctp_packet_config function in net/sctp/output.c in the Linux
          kernel before 2.6.35.6 performs extraneous initializations of packet data structures,
          which allows remote attackers to cause a denial of service (panic) via a certain sequence
          of SCTP traffic. CVE-2010-2962 drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution
          Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in
          the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory,
          which allows local users to write to arbitrary kernel memory locations, and consequently
          gain privileges, via crafted use of the ioctl interface, related to (1) pwrite and (2)
          pread operations. CVE-2010-2955 The cfg80211_wext_giwessid function in
          net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not
          properly initialize certain structure members, which allows local users to leverage an
          off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and
          obtain potentially sensitive information from kernel heap memory, via vectors involving an
          SIOCGIWESSID ioctl call that specifies a large buffer size. CVE-2010-3705 The
          sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does
          not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to
          cause a denial of service (memory corruption and panic) via a crafted value in the last
          element of this array. CVE-2010-3084 Buffer overflow in the niu_get_ethtool_tcam_all
          function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to
          cause a denial of service or possibly have unspecified other impact via the
          ETHTOOL_GRXCLSRLALL ethtool command. CVE-2010-3437 Integer signedness error in the
          pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before
          2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause
          a denial of service (invalid pointer dereference and system crash) via a crafted index
          value in a PKT_CTRL_CMD_STATUS ioctl call. CVE-2010-3079 kernel/trace/ftrace.c in the
          Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle
          interaction between mutex possession and llseek operations, which allows local users to
          cause a denial of service (NULL pointer dereference and outage of all function tracing
          files) via an lseek call on a file descriptor associated with the set_ftrace_filter file.
          CVE-2010-3698 The KVM implementation in the Linux kernel before 2.6.36 does not properly
          reload the FS and GS segment registers, which allows host OS users to cause a denial of
          service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local
          Descriptor Table (LDT). CVE-2010-3442 Multiple integer overflows in the snd_ctl_new
          function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow
          local users to cause a denial of service (heap memory corruption) or possibly have
          unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2)
          SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:45.009-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:43.097-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:41.689-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37239 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:36.600-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:31.101-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-100.24.1.el5" test_ref="oval:org.mitre.oval:tst:133902"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-100.24.1.el5" test_ref="oval:org.mitre.oval:tst:134841"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-100.24.1.el5" test_ref="oval:org.mitre.oval:tst:134672"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-100.24.1.el5" test_ref="oval:org.mitre.oval:tst:134796"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-100.24.1.el5" test_ref="oval:org.mitre.oval:tst:134194"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-100.24.1.el5" test_ref="oval:org.mitre.oval:tst:134447"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-100.24.1.el5" test_ref="oval:org.mitre.oval:tst:134781"/>
          <criterion comment="ofa-2.6.32-100.24.1.el5 is earlier than 0:1.5.1-4.0.23" test_ref="oval:org.mitre.oval:tst:134059"/>
          <criterion comment="ofa-2.6.32-100.24.1.el5debug is earlier than 0:1.5.1-4.0.23" test_ref="oval:org.mitre.oval:tst:134706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27701" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1061 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1061.html" ref_id="ELSA-2012-1061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3375" ref_id="CVE-2012-3375"/>
        <description>[2.6.18-308.11.1.el5]
- [net] ixgbe: remove flow director stats (Andy Gospodarek) [832169 830226]
- [net] ixgbe: fix default return value for ixgbe_cache_ring_fdir (Andy Gospodarek) [832169 830226]
- [net] ixgbe: reverting setup redirection table for multiple packet buffers (Andy Gospodarek) [832169 830226]

[2.6.18-308.10.1.el5]
- [xen] x86_64: check address on trap handlers or guest callbacks (Paolo Bonzini) [813430 813431] {CVE-2012-0217}
- [xen] x86_64: Do not execute sysret with a non-canonical return address (Paolo Bonzini) [813430 813431] {CVE-2012-0217}
- [xen] x86: prevent hv boot on AMD CPUs with Erratum 121 (Laszlo Ersek) [824969 824970] {CVE-2012-2934}
- [scsi] qla2xxx: Use ha->pdev->revision in 4Gbps MSI-X check. (Chad Dupuis) [816373 800653]
- [fs] sunrpc: do array overrun check in svc_recv before page alloc (J. Bruce Fields) [820358 814626]
- [fs] knfsd: fix an NFSD bug with full size non-page-aligned reads (J. Bruce Fields) [820358 814626]
- [fs] sunrpc: fix oops due to overrunning server's page array (J. Bruce Fields) [820358 814626]
- [fs] epoll: clear the tfile_check_list on -ELOOP (Jason Baron) [829670 817131]
- [x86_64] sched: Avoid unnecessary overflow in sched_clock (Prarit Bhargava) [824654 818787]
- [net] sunrpc: Don't use list_for_each_entry_safe in rpc_wake_up (Steve Dickson) [817571 809937]
- [s390] qeth: add missing wake_up call (Hendrik Brueckner) [829059 790900]

[2.6.18-308.9.1.el5]
- [fs] jbd: clear b_modified before moving the jh to a different transaction (Josef Bacik) [827205 563247]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:18.762-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.832-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:41.579-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:23:12.492-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:23:12.492-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131395"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.11.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130827"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.11.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131700"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131568"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131399"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131599"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:130723"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131650"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131720"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131585"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131273"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:131477"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.11.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131686"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.11.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131472"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.11.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131546"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.11.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131581"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.11.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131642"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.11.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131410"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27700" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0324 -- logwatch security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>logwatch</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0324.html" ref_id="ELSA-2011-0324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1018" ref_id="CVE-2011-1018"/>
        <description>[7.3.6-49]
- Added fix for CVE-2011-1018: Privilege escalation due improper
  sanitization of special characters in log file names
  Resolves: #680304</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:49.632-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.619-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:41.412-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:35:05.184-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:35:05.184-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="logwatch is earlier than 0:7.3-9.el5_6" test_ref="oval:org.mitre.oval:tst:134126"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="logwatch is earlier than 0:7.3.6-49.el6" test_ref="oval:org.mitre.oval:tst:134095"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27699" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2022 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2022.html" ref_id="ELSA-2012-2022"/>
        <description>[2.6.39-200.24.1.el5uek]
- Revert 'Add Oracle VM guest messaging driver' (Guru Anbalagane) [Orabug: 14233627}

[2.6.39-200.23.1.el5uek]
- SPEC: add block/net modules to list used by installer (Guru Anbalagane)
  [Orabug: 14224837]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:21.059-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.448-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:41.185-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131185"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131657"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131441"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131411"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131618"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131260"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131622"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131656"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131328"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131643"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131734"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131681"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27698" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2014 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2014.html" ref_id="ELSA-2012-2014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4086" ref_id="CVE-2011-4086"/>
        <description>kernel-uek: [2.6.32-300.25.1.el6uek] - jbd2: clear BH_Delay &amp; BH_Unwritten
          in journal_unmap_buffer (Eric Sandeen) [Bugdb: 13871] {CVE-2011-4086}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:06.149-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.213-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.995-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36392 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:37.020-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:30.543-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:132188"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131784"/>
            <criterion comment="ofa-2.6.32-300.25.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:132232"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131595"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131412"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:132044"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131270"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:132161"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131701"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132248"/>
            <criterion comment="ofa-2.6.32-300.25.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131776"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132095"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132131"/>
            <criterion comment="ofa-2.6.32-300.25.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:131496"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132031"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:131809"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:131867"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132269"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132205"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132118"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132201"/>
            <criterion comment="ofa-2.6.32-300.25.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132224"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27697" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1350 -- firefox security and bug fix update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1350.html" ref_id="ELSA-2012-1350"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1956" ref_id="CVE-2012-1956"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3982" ref_id="CVE-2012-3982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3986" ref_id="CVE-2012-3986"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3988" ref_id="CVE-2012-3988"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3990" ref_id="CVE-2012-3990"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3991" ref_id="CVE-2012-3991"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3992" ref_id="CVE-2012-3992"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3993" ref_id="CVE-2012-3993"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3994" ref_id="CVE-2012-3994"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3995" ref_id="CVE-2012-3995"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4179" ref_id="CVE-2012-4179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4180" ref_id="CVE-2012-4180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4181" ref_id="CVE-2012-4181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4182" ref_id="CVE-2012-4182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4183" ref_id="CVE-2012-4183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4184" ref_id="CVE-2012-4184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4185" ref_id="CVE-2012-4185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4186" ref_id="CVE-2012-4186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4187" ref_id="CVE-2012-4187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4188" ref_id="CVE-2012-4188"/>
        <description>firefox
[10.0.8-1.0.2.el6_3]
- Updated firefox-oracle-default-prefs.js based on latest firefox-redhat-default-prefs.js

[10.0.8-1.0.1.el6_3]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.8-1]
- Update to 10.0.8 ESR

xulrunner
[10.0.8-1.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.8-1]
- Update to 10.0.8 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:09.044-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.024-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.828-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:31:18.065-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:31:18.065-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.8-1.0.2.el5_8" test_ref="oval:org.mitre.oval:tst:130640"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130666"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130801"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.8-1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:131133"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130938"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130466"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27695" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0128 -- conga security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0128.html" ref_id="ELSA-2013-0128"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3359" ref_id="CVE-2012-3359"/>
        <description>[0.12.2-64.0.2.el5]

- Remove conga-enterprise.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:42.718-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:41.681-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.599-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:34:24.300-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:34:24.300-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="conga is earlier than 0:0.12.2-64.0.2.el5" test_ref="oval:org.mitre.oval:tst:130169"/>
          <criterion comment="luci is earlier than 0:0.12.2-64.0.2.el5" test_ref="oval:org.mitre.oval:tst:130636"/>
          <criterion comment="ricci is earlier than 0:0.12.2-64.0.2.el5" test_ref="oval:org.mitre.oval:tst:130696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27694" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1378 -- postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1378.html" ref_id="ELSA-2011-1378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2483" ref_id="CVE-2011-2483"/>
        <description>[8.4.9-1.el5_7.1]
- Update to PostgreSQL 8.4.9, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-9.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-8.html
  including the fix for CVE-2011-2483
Resolves: #740739</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:18.783-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:41.427-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.448-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:33:39.899-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:33:39.899-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql84 is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133340"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133173"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133314"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133091"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133170"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133129"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133241"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133371"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133332"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133201"/>
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133258"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132440"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27691" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1327 -- freeradius2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>freeradius2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1327.html" ref_id="ELSA-2012-1327"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3547" ref_id="CVE-2012-3547"/>
        <description>[2.1.12-4]
- resolves: bug#855315
  CVE-2012-3547 freeradius: Stack-based buffer overflow by processing
  certain expiration date fields of a certificate during x509 certificate
  validation</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:14.925-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:40.654-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:39.510-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:53:03.875-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:53:03.875-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="freeradius2 is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:131163"/>
          <criterion comment="freeradius2-krb5 is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:131080"/>
          <criterion comment="freeradius2-ldap is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:130932"/>
          <criterion comment="freeradius2-mysql is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:130879"/>
          <criterion comment="freeradius2-perl is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:130539"/>
          <criterion comment="freeradius2-postgresql is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:131097"/>
          <criterion comment="freeradius2-python is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:131179"/>
          <criterion comment="freeradius2-unixODBC is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:130571"/>
          <criterion comment="freeradius2-utils is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:131184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27689" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1073 -- bash security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1073.html" ref_id="ELSA-2011-1073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5374" ref_id="CVE-2008-5374"/>
        <description>[3.2-32]
- Dont include backup files
  Resolves: #700157

[3.2-31]
- Use 'mktemp' for temporary files
  Resolves: #700157

[3.2-30]
- Added man page references to systemwide .bash_logout
  Resolves: #592979

[3.2-29]
- Readline glitch, when editing line with more spaces and resizing window
  Resolves: #525474

[3.2-28]
- Fix the memory leak in read builtin
  Resolves: #618393
- Dont append slash to non-directories
  Resolves: #583919

[3.2-27]
- Test .dynamic section if has PROGBITS or NOBITS
  Resolves: #484809
- Better random number generator
  Resolves: #492908
- Allow to source scripts with embeded NULL chars
  Resolves: #503701

[3.2-26]
- vi mode redo insert fixed
  Resolves: #575076
- Dont show broken pipe messages for builtins
  Resolves: #546529
- Dont include loadables in doc dir
  Resolves: #663656
- Enable system-wide .bash_logout for login shells
  Resolves: #592979

[3.2-25]
- Dont abort source builtin
  Resolves: #448508
- Correctly place cursor
  Resolves: #463880
- Minor man page clarification for trap builtin
  Resolves: #504904</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:19.147-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:39.823-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:38.856-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:28:44.351-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:28:44.351-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="bash is earlier than 0:3.2-32.el5" test_ref="oval:org.mitre.oval:tst:133441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27688" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-1323-1 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1323-1.html" ref_id="ELSA-2012-1323-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3430" ref_id="CVE-2012-3430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2319" ref_id="CVE-2012-2319"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3510" ref_id="CVE-2012-3510"/>
        <description>kernel [2.6.18-308.16.1.0.1.el5] - [kernel] Initialize the local uninitialized
          variable stats. [orabug 14051367] - [fs] JBD:make jbd support 512B blocks correctly for
          ocfs2. [orabug 13477763] - [x86 ] fix fpu context corrupt when preempt in signal context
          [orabug 14038272] - [net] bonding: fix carrier detect when bond is down [orabug 12377284]
          - [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075] - fix ia64 build error due
          to add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use dynamic vcpu_info remap to
          support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0 reset when hvm boot up with
          noapic param - [scsi] remove printks when doing I/O to a dead device (John Sobecki, Chris
          Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin)
          [orabug 12561346] - [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
          - [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
          - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646] -
          [scsi] fix scsi hotplug and rescan race [orabug 10260172] - fix filp_close() race (Joe
          Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default [orabug 67188919] - [xen]
          check to see if hypervisor supports memory reservation change (Chuck Anderson) [orabug
          7556514] - [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John
          Sobecki) [orabug 10315433] - [NET] Add xen pv netconsole support (Tina Yang) [orabug
          6993043] [bz 7258] - [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839] -
          fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042] - [rds] Patch rds to
          1.4.2-20 (Andy Grover) [orabug 9471572, 9344105] RDS: Fix BUG_ONs to not fire when in a
          tasklet ipoib: Fix lockup of the tx queue RDS: Do not call set_page_dirty() with irqs off
          (Sherman Pun) RDS: Properly unmap when getting a remote access error (Tina Yang) RDS: Fix
          locking in rds_send_drop_to() - [xen] PVHVM guest with PoD crashes under memory pressure
          (Chuck Anderson) [orabug 9107465] - [xen] PV guest with FC HBA hangs during shutdown
          (Chuck Anderson) [orabug 9764220] - Support 256GB+ memory for pv guest (Mukesh Rathor)
          [orabug 9450615] - fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
          Guru Anbalagane) [orabug 6124033] - [ipmi] make configurable timeouts for kcs of ipmi
          [orabug 9752208] - [ib] fix memory corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:09.924-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:39.375-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:38.636-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35820 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:37.241-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:30.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130945"/>
          <criterion comment="ocfs2-2.6.18-308.16.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130593"/>
          <criterion comment="oracleasm-2.6.18-308.16.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130788"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131030"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131050"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130775"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131176"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130749"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131111"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131046"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130425"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131129"/>
          <criterion comment="ocfs2-2.6.18-308.16.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130851"/>
          <criterion comment="ocfs2-2.6.18-308.16.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130235"/>
          <criterion comment="ocfs2-2.6.18-308.16.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131036"/>
          <criterion comment="oracleasm-2.6.18-308.16.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130485"/>
          <criterion comment="oracleasm-2.6.18-308.16.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130381"/>
          <criterion comment="oracleasm-2.6.18-308.16.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130499"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27685" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0567 -- lvm2-cluster security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>lvm2-cluster</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0567.html" ref_id="ELSA-2010-0567"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2526" ref_id="CVE-2010-2526"/>
        <description>[2.02.56-el5_5.4]
- CVE-2010-2526: Fix insecurity when communicating between lvm2 and clvmd.
  Resolves: #616044</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:09.253-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:38.651-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:38.189-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:40:59.890-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:40:59.890-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="lvm2-cluster is earlier than 0:2.02.56-7.el5_5.4" test_ref="oval:org.mitre.oval:tst:134908"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27682" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0407 -- libpng security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0407.html" ref_id="ELSA-2012-0407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3045" ref_id="CVE-2011-3045"/>
        <description>[2:1.2.48-1]
- Update to libpng 1.2.48, for minor security issues (CVE-2011-3045)
Resolves: #801663</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:00.610-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:37.845-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:37.764-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:51:12.432-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:51:12.432-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:131984"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:132507"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:132033"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:132549"/>
            <criterion comment="libpng-static is earlier than 0:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:132552"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27680" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0302 -- cups security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0302.html" ref_id="ELSA-2012-0302"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2896" ref_id="CVE-2011-2896"/>
        <description>[1:1.3.7-30]
- Backported patch to fix transcoding for ASCII (bug #759081, STR #3832).

[1:1.3.7-29]
- The imageto* filters could crash with bad GIF files
  (CVE-2011-2896, STR #3867, STR #3914, bug #752118).

[1:1.3.7-28]
- Web interface didn't show completed jobs for printer (STR #3436, bug #625900)
- Serial backend didn't allow a raw job to be canceled (STR #3649, bug #625955)
- Fixed condition in textonly filter to create temporary file
  regardless of the number of copies specified. (bug #660518)

[1:1.3.7-27]
- Call avc_init() only once to not leak file descriptors (bug #668009).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:14.081-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:37.304-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:37.341-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:10:57.745-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:10:57.745-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups is earlier than 0:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:132450"/>
          <criterion comment="cups-devel is earlier than 0:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:132594"/>
          <criterion comment="cups-libs is earlier than 0:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:132164"/>
          <criterion comment="cups-lpd is earlier than 0:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:132621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27672" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2008 -- Unbreakable Enterprise kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2008.html" ref_id="ELSA-2012-2008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1090" ref_id="CVE-2012-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1097" ref_id="CVE-2012-1097"/>
        <description>[2.6.39-100.6.1]

- regset: Return -EFAULT, not -EIO, on host-side memory fault (H. Peter Anvin)

  {CVE-2012-1097}

- regset: Prevent null pointer reference on readonly regsets (H. Peter Anvin)

  {CVE-2012-1097}

- cifs: fix dentry refcount leak when opening a FIFO on lookup (Jeff Layton)

  {CVE-2012-1090}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:23.671-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:35.684-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.506-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132392"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132307"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132329"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132010"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132358"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132007"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132514"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132474"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132369"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132245"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132340"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:131798"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27671" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-0151 -- conga security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0151.html" ref_id="ELSA-2012-0151"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1104" ref_id="CVE-2010-1104"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1948" ref_id="CVE-2011-1948"/>
        <description>[0.12.2-51.0.1.el5]
- Added conga-enterprise.patch
- Added conga-enterprise-Carthage.patch to support OEL5
- Replaced redhat logo image in conga-0.12.2.tar.gz

[0.12.2-51]
- Fix bz711494 (CVE-2011-1948 plone: reflected XSS vulnerability)
- Fix bz771920 (CVE-2011-4924 Zope: Incomplete upstream patch for CVE-2010-1104/bz577019)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:12.524-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:35.380-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.367-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="conga is earlier than 0:0.12.2-51.0.1.el5" test_ref="oval:org.mitre.oval:tst:132670"/>
          <criterion comment="luci is earlier than 0:0.12.2-51.0.1.el5" test_ref="oval:org.mitre.oval:tst:132671"/>
          <criterion comment="ricci is earlier than 0:0.12.2-51.0.1.el5" test_ref="oval:org.mitre.oval:tst:132493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27670" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0180 -- mysql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0180.html" ref_id="ELSA-2013-0180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2749" ref_id="CVE-2012-2749"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5611" ref_id="CVE-2012-5611"/>
        <description>[5.0.95-5]
- Rebuild to fix wrong package tag
Related: #892679

[5.0.95-4]
- Add patches for CVE-2012-2122, CVE-2012-2749, CVE-2012-5611
Resolves: #892679</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:36.387-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:35.149-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.193-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:27:40.094-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:27:40.094-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:129728"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:130585"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:129858"/>
          <criterion comment="mysql-server is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:130535"/>
          <criterion comment="mysql-test is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:130598"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27669" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0565 -- w3m security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>w3m</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0565.html" ref_id="ELSA-2010-0565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2074" ref_id="CVE-2010-2074"/>
        <description>[0.5.1-17]
- Resolves:rh#604861:Clear execstack requirement also for ia64 architecture

[0.5.1-16]
- Resolves:rh#604861:CVE-2010-2074 w3m: doesn't handle NULL in Common Name properly</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:16.370-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:34.935-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.026-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:04:13.871-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:04:13.871-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="w3m is earlier than 0:0.5.1-17.el5_5" test_ref="oval:org.mitre.oval:tst:134580"/>
          <criterion comment="w3m-img is earlier than 0:0.5.1-17.el5_5" test_ref="oval:org.mitre.oval:tst:135058"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27668" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3105 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3105.html" ref_id="ELSA-2014-3105"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3184" ref_id="CVE-2014-3184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" ref_id="CVE-2014-3688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4652" ref_id="CVE-2014-4652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4656" ref_id="CVE-2014-4656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" ref_id="CVE-2014-6410"/>
        <description>kernel-uek [2.6.32-400.36.12] - HID: fix a couple of off-by-ones (Jiri Kosina)
          [Orabug: 19849320] {CVE-2014-3184} - ALSA: control: Protect user controls against
          concurrent access (Lars-Peter Clausen) [Orabug: 20192545] {CVE-2014-4652} - udf: Avoid
          infinite loop when processing indirect ICBs (Jan Kara) [Orabug: 20192451] {CVE-2014-6410}
          - ALSA: control: Make sure that id->index does not overflow (Lars-Peter Clausen)
          [Orabug: 20192420] {CVE-2014-4656} - ALSA: control: Handle numid overflow (Lars-Peter
          Clausen) [Orabug: 20192379] {CVE-2014-4656} - net: sctp: fix remote memory pressure from
          excessive queueing (Daniel Borkmann) [Orabug: 20192060] {CVE-2014-3688}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:25.600-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:08.979-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:02.660-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37823 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:40.509-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:29.276-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:137071"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136721"/>
            <criterion comment="ofa-2.6.32-400.36.12.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136792"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136144"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:137120"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136478"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136589"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136960"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:137128"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136412"/>
            <criterion comment="ofa-2.6.32-400.36.12.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136534"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136815"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136913"/>
            <criterion comment="ofa-2.6.32-400.36.12.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136877"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136369"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136977"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:137123"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136980"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:137073"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136377"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136971"/>
            <criterion comment="ofa-2.6.32-400.36.12.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:137075"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27665" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0787 -- glibc security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0787.html" ref_id="ELSA-2010-0787"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3847" ref_id="CVE-2010-3847"/>
        <description>[2.5-49.el5_5.6]
- Never expand  in privileged programs (#643818, CVE-2010-3847)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:56.430-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:34.573-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:35.698-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:38:10.960-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:38:10.960-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:134172"/>
          <criterion comment="glibc-common is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:134800"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:134870"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:134888"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:134763"/>
          <criterion comment="nscd is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:134720"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27664" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0376 -- systemtap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0376.html" ref_id="ELSA-2012-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0875" ref_id="CVE-2012-0875"/>
        <description>[1.6-5.0.1.el6_2]

- remove doc/SystemTap_Beginners_Guide/en-US in tarball

- comment bz683569.patch in specfile

- remove buildtime dependency on package publican-redhat



[1.6-5]

- CVE-2012-0875</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:30.043-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:34.307-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:35.513-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:15:11.208-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:15:11.208-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132402"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132611"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:131898"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:131755"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132302"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132372"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132251"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132341"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132598"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132584"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132062"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132437"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132566"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27662" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0847 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0847.html" ref_id="ELSA-2013-0847"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0153" ref_id="CVE-2013-0153"/>
        <description>kernel
[2.6.18-348.6.1]
- [char] ipmi: use a tasklet for handling received messages (Tony Camuso) [953435 947732]
- [char] ipmi: do run_to_completion properly in deliver_recv_msg (Tony Camuso) [953435 947732]
- [fs] nfs4: fix locking around cl_state_owners list (Dave Wysochanski) [954296 948317]
- [fs] nfs: Fix bugs on short read (Sachin Prabhu) [952098 924011]
- [xen] AMD IOMMU: spot missing IO-APIC entries in IVRS table (Igor Mammedov) [910912 910913] {CVE-2013-0153}
- [xen] AMD, IOMMU: Make per-device interrupt remap table default (Igor Mammedov) [910912 910913] {CVE-2013-0153}
- [xen] AMD, IOMMU: Disable IOMMU if SATA Combined mode is on (Igor Mammedov) [910912 910913] {CVE-2013-0153}
- [xen] AMD, IOMMU: On creating entry clean up in remapping tables (Igor Mammedov) [910912 910913] {CVE-2013-0153}
- [xen] ACPI: acpi_table_parse() should return handler's err code (Igor Mammedov) [910912 910913] {CVE-2013-0153}
- [xen] introduce xzalloc() &amp; Co (Igor Mammedov) [910912 910913] {CVE-2013-0153}
- [x86] fpu: fix CONFIG_PREEMPT=y corruption of FPU stack (Prarit Bhargava) [948187 731531]
- [i386] add sleazy FPU optimization (Prarit Bhargava) [948187 731531]
- [x86-64] non lazy 'sleazy' fpu implementation (Prarit Bhargava) [948187 731531]

[2.6.18-348.5.1]
- [fs] nfs: handle getattr failure during nfsv4 open (David Jeffery) [947736 906909]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:23.545-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:33.834-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:35.174-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:55:55.779-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:55:55.779-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:128762"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.6.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129383"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.6.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128831"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:129221"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:129259"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:128597"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:129578"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:129473"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:129522"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:129517"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:128771"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:129573"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.6.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129560"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.6.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129482"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.6.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129514"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.6.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129586"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.6.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129399"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.6.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129551"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27659" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0095 -- ghostscript security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0095.html" ref_id="ELSA-2012-0095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3743" ref_id="CVE-2009-3743"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2055" ref_id="CVE-2010-2055"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4054" ref_id="CVE-2010-4054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4820" ref_id="CVE-2010-4820"/>
        <description>[8.70-11:.6]
- Applied upstream fix to last patch (CVE-2010-4054, bug #646086).

[8.70-11:.5]
- Applied patch to prevent null pointer dereference (CVE-2010-4054,
  bug #646086).

[8.70-11:.4]
- Don't ship patch backup files for CVE-2010-2055.

[8.70-11:.3]
- Applied patch to prevent integer underflow in TrueType bytecode
  interpreter (CVE-2009-3743, bug #627902).
- Applied patch to avoid reading initialization files from CWD
  (CVE-2010-2055, bug #599564).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:23.214-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:33.101-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:34.761-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:37:22.025-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:37:22.025-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:132561"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:132781"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:132558"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132285"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132741"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132522"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132401"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27657" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2504 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2504.html" ref_id="ELSA-2013-2504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4530" ref_id="CVE-2012-4530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0190" ref_id="CVE-2013-0190"/>
        <description>[2.6.32-300.39.4] - exec: do not leave bprm->interp on stack (Kees Cook)
          [Orabug: 16286741] {CVE-2012-4530} - exec: use -ELOOP for max recursion depth (Kees Cook)
          [Orabug: 16286741] {CVE-2012-4530} [2.6.32-300.39.3] - Xen: Fix stack corruption in
          xen_failsafe_callback for 32bit PVOPS guests. (Frediano Ziglio) [Orabug: 16274192]
          {CVE-2013-0190}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:51.796-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:32.459-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:34.170-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36004 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:40.805-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:28.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130480"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130517"/>
            <criterion comment="ofa-2.6.32-300.39.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130440"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130486"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130066"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130444"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:129674"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130108"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130297"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130454"/>
            <criterion comment="ofa-2.6.32-300.39.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130472"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130113"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130483"/>
            <criterion comment="ofa-2.6.32-300.39.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130426"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130202"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130461"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130465"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130396"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130451"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130224"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130026"/>
            <criterion comment="ofa-2.6.32-300.39.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27656" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0033 -- php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0033.html" ref_id="ELSA-2012-0033"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4566" ref_id="CVE-2011-4566"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4885" ref_id="CVE-2011-4885"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0708" ref_id="CVE-2011-0708"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1148" ref_id="CVE-2011-1148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1466" ref_id="CVE-2011-1466"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1469" ref_id="CVE-2011-1469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2202" ref_id="CVE-2011-2202"/>
        <description>[5.1.6-27.4]
- add security fixes for CVE-2011-4885, CVE-2011-4566, CVE-2011-0708,
  CVE-2011-1148, CVE-2011-1466, CVE-2011-1469, CVE-2011-2202 (#769756)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:22.723-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:31.585-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:33.624-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:13:19.071-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:13:19.071-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132836"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132103"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132680"/>
          <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132356"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132838"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132748"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132816"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132804"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132868"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132439"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132923"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132695"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132914"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132795"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132818"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132703"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132882"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132872"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:132907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27655" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0124 -- net-snmp security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0124.html" ref_id="ELSA-2013-0124"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2141" ref_id="CVE-2012-2141"/>
        <description>[5.3.2.2-20.0.1.el5]

- suppress spurious asserts on 32bit [Greg Marsden]
[5.3.2.2-20]

- fixed error message when the address specified by clientaddr option

  is wrong or cannot be bound (#840861)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:55.147-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:31.227-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:33.435-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:19:06.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:19:06.927-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="net-snmp is earlier than 0:5.3.2.2-20.0.2.el5" test_ref="oval:org.mitre.oval:tst:130671"/>
          <criterion comment="net-snmp-devel is earlier than 0:5.3.2.2-20.0.2.el5" test_ref="oval:org.mitre.oval:tst:130555"/>
          <criterion comment="net-snmp-libs is earlier than 0:5.3.2.2-20.0.2.el5" test_ref="oval:org.mitre.oval:tst:130208"/>
          <criterion comment="net-snmp-perl is earlier than 0:5.3.2.2-20.0.2.el5" test_ref="oval:org.mitre.oval:tst:130475"/>
          <criterion comment="net-snmp-utils is earlier than 0:5.3.2.2-20.0.2.el5" test_ref="oval:org.mitre.oval:tst:130528"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27654" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2507 -- Unbreakable Enterprise kernel security  and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2507.html" ref_id="ELSA-2013-2507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0228" ref_id="CVE-2013-0228"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0309" ref_id="CVE-2013-0309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0311" ref_id="CVE-2013-0311"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0310" ref_id="CVE-2013-0310"/>
        <description>[2.6.39-400.17.1] 

- This is a fix on dlm_clean_master_list() (Xiaowei.Hu) 

- RDS: fix rds-ping spinlock recursion (jeff.liu) [Orabug: 16223050] 

- vhost: fix length for cross region descriptor (Michael S. Tsirkin) [Orabug: 

16387183] {CVE-2013-0311} 

- kabifix: block/scsi: Allow request and error handling timeouts to be 

specified (Maxim Uvarov) 

- block/scsi: Allow request and error handling timeouts to be specified (Martin 

K. Petersen) [Orabug: 16372401] 

- [SCSI] Shorten the path length of scsi_cmd_to_driver() (Li Zhong) [Orabug: 

16372401] 

- Fix NULL dereferences in scsi_cmd_to_driver (Mark Rustad) [Orabug: 16372401] 

- SCSI: Fix error handling when no ULD is attached (Martin K. Petersen) 

[Orabug: 16372401] 

- Handle disk devices which can not process medium access commands (Martin K. 

Petersen) [Orabug: 16372401] 

- the ac->ac_allow_chain_relink=0 won't disable group relink (Xiaowei.Hu) 

[Orabug: 14842737] 

- pci: hotplug: fix null dereference in pci_set_payload() (Jerry Snitselaar) 

[Orabug: 16345420]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:59.368-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:30.923-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:33.150-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130249"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130255"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130212"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:129353"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130175"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130234"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130275"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:129989"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130012"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130186"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130304"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:129991"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27652" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-0303 -- xorg-x11-server security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0303.html" ref_id="ELSA-2012-0303"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4028" ref_id="CVE-2011-4028"/>
        <description>[1.1.1-48.90.0.1.el5]
- Added oracle-enterprise-detect.patch
- Replaced 'Red Hat' in spec file

[1.1.1-48.90]
- cve-2011-4028.patch: File existence disclosure vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:16.610-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:30.544-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:32.807-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:132647"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:132208"/>
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:131804"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:132646"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:132384"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:132160"/>
          <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:131912"/>
          <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.90.0.1.el5" test_ref="oval:org.mitre.oval:tst:132716"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27648" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2035 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2035.html" ref_id="ELSA-2012-2035"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313" ref_id="CVE-2012-2313"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2390" ref_id="CVE-2012-2390"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3430" ref_id="CVE-2012-3430"/>
        <description>[2.6.32-300.32.3] - dl2k: Clean up rio_ioctl (Stephan Mueller) [Orabug:
          14675306] {CVE-2012-2313} - hugetlb: fix resv_map leak in error path (Christoph Lameter)
          [Orabug: 14676403] {CVE-2012-2390} - rds: set correct msg_namelen (Jay Fenlason) [Orabug:
          14676504] {CVE-2012-3430}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:26.101-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:28.964-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.879-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36021 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:38.357-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:27.868-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130717"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130427"/>
            <criterion comment="ofa-2.6.32-300.32.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130953"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130978"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130222"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130974"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:131157"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130850"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130561"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131094"/>
            <criterion comment="ofa-2.6.32-300.32.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131197"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131119"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130820"/>
            <criterion comment="ofa-2.6.32-300.32.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130971"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:130643"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:130795"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131062"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:130814"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131201"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131169"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130602"/>
            <criterion comment="ofa-2.6.32-300.32.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130889"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27647" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0690 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0690.html" ref_id="ELSA-2012-0690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2136" ref_id="CVE-2012-2136"/>
        <description>[2.6.18-308.8.1.el5]
- [net] sock: validate data_len before allocating skb in sock_alloc_send_pskb() (Jason Wang) [816290 816106] {CVE-2012-2136}
- [net] tg3: Fix VLAN tagging assignments (John Feeney) [817691 797011]
- [net] ixgbe: do not stop stripping VLAN tags in promiscuous mode (Andy Gospodarek) [809791 804800]
- [s390] zcrypt: Fix parameter checking for ZSECSENDCPRB ioctl (Hendrik Brueckner) [810123 808489]
- [x86] unwind information fix for the vsyscall DSO (Prarit Bhargava) [807930 805799]

[2.6.18-308.7.1.el5]
- [fs] epoll: Don't limit non-nested epoll paths (Jason Baron) [809380 804778]

[2.6.18-308.6.1.el5]
- [scsi] fc class: fix scanning when devs are offline (Mike Christie) [816684 799530]
- [md] dm-multipath: delay retry of bypassed pg (Mike Christie) [816684 799530]
- [net] bonding: properly unset current_arp_slave on slave link up (Veaceslav Falico) [811927 800575]
- [net] bonding: remove {master,vlan}_ip and query devices instead (Andy Gospodarek) [810321 772216]

[2.6.18-308.5.1.el5]
- [scsi] skip sense logging for some ATA PASS-THROUGH cdbs (David Milburn) [807265 788777]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:18.863-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:28.799-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.746-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:32:53.141-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:32:53.141-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:131407"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.1.el5-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:131156"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132137"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:131848"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:131812"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:132152"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:131982"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:131975"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:132058"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:132040"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:132064"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.8.1.el5" test_ref="oval:org.mitre.oval:tst:131832"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.1.el5PAE-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:131952"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.1.el5debug-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132017"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.8.1.el5xen-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132091"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131836"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131211"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.8.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27644" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0594 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0594.html" ref_id="ELSA-2013-0594"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3400" ref_id="CVE-2012-3400"/>
        <description>kernel
[2.6.18-348.2.1]
- [misc] tainted flags, fix buffer size (Prarit Bhargava) [905829 901547]
- [net] be2net: fix unconditionally returning IRQ_HANDLED in INTx (Ivan Vecera) [884704 878316]
- [net] be2net: fix INTx ISR for interrupt behaviour on BE2 (Ivan Vecera) [884704 878316]
- [net] be2net: fix a possible events_get() race on BE2 (Ivan Vecera) [884704 878316]
- [firmware] Expand kernel boot-time storage for DMI table structs (Lenny Szubowicz) [902683 862865]
- [fs] udf: Fortify loading of sparing table (Nikola Pajkovsky) [843140 843141] {CVE-2012-3400}
- [fs] udf: Improve table length check to avoid possible overflow (Nikola Pajkovsky) [843140 843141] {CVE-2012-3400}
- [fs] udf: Avoid run away loop when partition table is corrupted (Nikola Pajkovsky) [843140 843141] {CVE-2012-3400}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:00.622-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:28.040-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.410-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:33:46.003-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:33:46.003-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:130016"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.2.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129869"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.2.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129446"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:130017"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:130149"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:130103"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:129767"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:129925"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:130092"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:130128"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:129891"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:129965"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.2.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129999"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.2.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130123"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.2.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129996"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.2.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129851"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.2.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130154"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.2.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27641" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0608 -- kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0608.html" ref_id="ELSA-2013-0608"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6075" ref_id="CVE-2012-6075"/>
        <description>[kvm-83-262.0.1.el5_9.1]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch

[kvm-83-262.el5_1]
- kvm-e1000-Discard-packets-that-are-too-long-if-SBP-and-L.patch [bz#910839]
- kvm-e1000-Discard-oversized-packets-based-on-SBP-LPE.patch [bz#910839]
- Resolves: bz#910839
  (CVE-2012-6075  qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [rhel-5.9.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:51.205-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:27.485-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.157-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:20:31.399-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:20:31.399-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-262.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130069"/>
          <criterion comment="kmod-kvm is earlier than 0:83-262.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:129952"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-262.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130138"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-262.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130046"/>
          <criterion comment="kvm-tools is earlier than 0:83-262.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:129550"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27640" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0506 -- rdesktop security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rdesktop</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0506.html" ref_id="ELSA-2011-0506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1595" ref_id="CVE-2011-1595"/>
        <description>[1.6.0-8.1]
- Prevent remote file access (#676252)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:57.454-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:27.320-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.019-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:16:09.026-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:16:09.026-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="rdesktop is earlier than 0:1.6.0-3.el5_6.2" test_ref="oval:org.mitre.oval:tst:133996"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="rdesktop is earlier than 0:1.6.0-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:133812"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27638" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0627 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0627.html" ref_id="ELSA-2013-0627"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0787" ref_id="CVE-2013-0787"/>
        <description>[17.0.3-2.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.3-2]
- Added fix for #848644</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:46.284-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:26.914-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:30.824-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:11:41.073-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:11:41.073-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129156"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129923"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27635" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-0721-1 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0721-1.html" ref_id="ELSA-2012-0721-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0217" ref_id="CVE-2012-0217"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2934" ref_id="CVE-2012-2934"/>
        <description>kernel: [2.6.18-308.8.2.0.1.el5] - [net] bonding: fix carrier detect when bond
          is down [orabug 12377284] - [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
          - fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use
          dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0
          reset when hvm boot up with noapic param - [scsi] remove printk's when doing I/O to a dead
          device (John Sobecki, Chris Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to
          timing problems (Joe Jin) [orabug 12561346] - [scsi] Fix race when removing SCSI devices
          (Joe Jin) [orabug 12404566] - [net] net: Redo the broken redhat netconsole over bonding
          (Tina Yang) [orabug 12740042] - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic
          (Joe Jin) [orabug 12687646] - [scsi] fix scsi hotplug and rescan race [orabug 10260172] -
          fix filp_close() race (Joe Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default
          [orabug 67188919] - [xen] check to see if hypervisor supports memory reservation change
          (Chuck Anderson) [orabug 7556514] - [net] Enable entropy for
          bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki) [orabug 10315433] - [NET] Add xen
          pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258] - [mm] shrink_zone patch
          (John Sobecki,Chris Mason) [orabug 6086839] - fix aacraid not to reset during kexec (Joe
          Jin) [orabug 8516042] - [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572,
          9344105] RDS: Fix BUG_ONs to not fire when in a tasklet ipoib: Fix lockup of the tx queue
          RDS: Do not call set_page_dirty() with irqs off (Sherman Pun) RDS: Properly unmap when
          getting a remote access error (Tina Yang) RDS: Fix locking in rds_send_drop_to() - [xen]
          PVHVM guest with PoD crashes under memory pressure (Chuck Anderson) [orabug 9107465] +-
          [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson) [orabug 9764220] -
          Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615] - fix overcommit
          memory to use percpu_counter for el5 (KOSAKI Motohiro, Guru Anbalagane) [orabug 6124033] -
          [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208] - [ib] fix memory
          corruption (Andy Grover) [orabug 9972346] [2.6.18-308.8.2.el5] - [xen] x86_64: check
          address on trap handlers or guest callbacks (Paolo Bonzini) [813430 813431]
          {CVE-2012-0217} - [xen] x86_64: Do not execute sysret with a non-canonical return address
          (Paolo Bonzini) [813430 813431] {CVE-2012-0217} - [xen] x86: prevent hv boot on AMD CPUs
          with Erratum 121 (Laszlo Ersek) [824969 824970]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:30.035-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:26.292-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:30.480-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35684 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:42.206-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:27.413-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131959"/>
          <criterion comment="ocfs2-2.6.18-308.8.2.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131426"/>
          <criterion comment="oracleasm-2.6.18-308.8.2.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131986"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131870"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131887"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:132005"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131773"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131203"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131968"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131782"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131933"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.8.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:131927"/>
          <criterion comment="ocfs2-2.6.18-308.8.2.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131775"/>
          <criterion comment="ocfs2-2.6.18-308.8.2.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131875"/>
          <criterion comment="ocfs2-2.6.18-308.8.2.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131526"/>
          <criterion comment="oracleasm-2.6.18-308.8.2.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131780"/>
          <criterion comment="oracleasm-2.6.18-308.8.2.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131978"/>
          <criterion comment="oracleasm-2.6.18-308.8.2.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131903"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27634" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0685 -- perl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0685.html" ref_id="ELSA-2013-0685"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5195" ref_id="CVE-2012-5195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1667" ref_id="CVE-2013-1667"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5526" ref_id="CVE-2012-5526"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6329" ref_id="CVE-2012-6329"/>
        <description>[4:5.10.1-130]
- Resolves: #915692 - CVE-2012-5526 (newline injection due to improper CRLF
  escaping in Set-Cookie and P3P headers)
- Resolves: #915692 - CVE-2012-6329 (possible arbitrary code execution via
  Locale::Maketext)
- Resolves: #915692 - CVE-2013-1667 (DoS in rehashing code)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:58.974-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:25.701-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:29.918-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:18:35.217-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:18:35.217-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="perl is earlier than 0:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:129844"/>
            <criterion comment="perl-suidperl is earlier than 0:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:129536"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="perl is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129757"/>
            <criterion comment="perl-Archive-Extract is earlier than 0:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:129433"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:129687"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:129745"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:129177"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:129007"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129862"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129628"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129690"/>
            <criterion comment="perl-Digest-SHA is earlier than 0:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:129832"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 0:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:129711"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:129063"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:129774"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 0:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:128898"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:129751"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129827"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129565"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129583"/>
            <criterion comment="perl-IO-Zlib is earlier than 0:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:129836"/>
            <criterion comment="perl-IPC-Cmd is earlier than 0:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:129723"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 0:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:129644"/>
            <criterion comment="perl-Log-Message is earlier than 0:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:129840"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:129892"/>
            <criterion comment="perl-Module-Build is earlier than 0:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:129782"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:129527"/>
            <criterion comment="perl-Module-Load is earlier than 0:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:129080"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:129335"/>
            <criterion comment="perl-Module-Loaded is earlier than 0:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:129880"/>
            <criterion comment="perl-Module-Pluggable is earlier than 0:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:129413"/>
            <criterion comment="perl-Object-Accessor is earlier than 0:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:129558"/>
            <criterion comment="perl-Package-Constants is earlier than 0:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:129868"/>
            <criterion comment="perl-Params-Check is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:129215"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 0:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:129475"/>
            <criterion comment="perl-Pod-Escapes is earlier than 0:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:129587"/>
            <criterion comment="perl-Pod-Simple is earlier than 0:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:129817"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:128944"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:129808"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:129890"/>
            <criterion comment="perl-Time-HiRes is earlier than 0:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:129416"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:129831"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129821"/>
            <criterion comment="perl-devel is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129392"/>
            <criterion comment="perl-libs is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129741"/>
            <criterion comment="perl-parent is earlier than 0:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:129916"/>
            <criterion comment="perl-suidperl is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129732"/>
            <criterion comment="perl-version is earlier than 0:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:129798"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27632" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0545 -- ImageMagick security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0545.html" ref_id="ELSA-2012-0545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0247" ref_id="CVE-2012-0247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0248" ref_id="CVE-2012-0248"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0260" ref_id="CVE-2012-0260"/>
        <description>[6.2.8.0-15.el5]
- Fix for PostScript conversion was incomplete, as larger documents
  would end up being cropped without the -g option (797364)

[6.2.8.0-14.el5]
- Add fix for CVE-2012-0247 CVE-2012-0248 CVE-2012-1185 CVE-2012-1186
- Add fix for CVE-2012-0259 CVE-2012-0260 CVE-2012-1798

[6.2.8.0-13.el5]
- Fix PostScript conversion failing with /undefinedfilename (797364)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:28.062-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:24.920-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:29.502-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:02:32.860-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:02:32.860-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:132121"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:132419"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:132282"/>
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:132306"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:131423"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27630" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1174 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1174.html" ref_id="ELSA-2012-1174"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313" ref_id="CVE-2012-2313"/>
        <description>kernel
[2.6.18-308.13.1.el5]
- [net] e1000e: Cleanup logic in e1000_check_for_serdes_link_82571 (Dean Nelson) [841370 771366]
- [net] e1000e: Correct link check logic for 82571 serdes (Dean Nelson) [841370 771366]
- [mm] NULL pointer dereference in __vm_enough_memory (Jerome Marchand) [840077 836244]
- [fs] dlm: fix slow rsb search in dir recovery (David Teigland) [838140 753244]
- [fs] autofs: propogate LOOKUP_DIRECTORY flag only for last comp (Ian Kent) [830264 814418]
- [fs] ext4: properly dirty split extent nodes (Eric Sandeen) [840946 839770]
- [scsi] don't offline devices with a reservation conflict (David Jeffery) [839196 835660]
- [fs] ext4: Fix overflow caused by missing cast in ext4_fallocate (Lukas Czerner) [837226 830351]
- [net] dl2k: Clean up rio_ioctl (Weiping Pan) [818822 818823] {CVE-2012-2313}
- [x86] sched: Avoid unnecessary overflow in sched_clock (Prarit Bhargava) [835450 834562]
- [net] tg3: Fix TSO handling (John Feeney) [833182 795672]
- [input] evdev: use after free from open/disconnect race (David Jeffery) [832448 822166]

[2.6.18-308.12.1.el5]
- [fs] nfs: Don't allow multiple mounts on same mntpnt with -o noac (Sachin Prabhu) [839806 839753]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:36.025-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:24.554-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:29.183-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:55:07.380-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:55:07.380-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:130683"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.13.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131134"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.13.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131290"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:131243"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:131229"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:131298"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:131275"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:131216"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:130729"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:130613"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:131165"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:131142"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.13.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131312"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.13.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131123"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.13.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130601"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.13.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131338"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.13.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131365"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.13.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131299"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27629" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2048 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2048.html" ref_id="ELSA-2012-2048"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2100" ref_id="CVE-2012-2100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4444" ref_id="CVE-2012-4444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4565" ref_id="CVE-2012-4565"/>
        <description>[2.6.32-300.39.2] - ext4: fix undefined behavior in ext4_fill_flex_info() (Xi
          Wang) [orabug 16020245] {CVE-2012-2100} - Divide by zero in TCP congestion control
          Algorithm (Jesper Dangaard Brouer) [orabug 16020447] {CVE-2012-4565} - ipv6: discard
          overlapping fragment (Luis Henriques) [orabug 16021354] {CVE-2012-4444}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:26.780-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:24.139-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.858-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36084 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:37.465-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:26.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130296"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130390"/>
            <criterion comment="ofa-2.6.32-300.39.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130753"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130767"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130752"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:129823"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130607"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130595"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130804"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130787"/>
            <criterion comment="ofa-2.6.32-300.39.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130819"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130761"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130541"/>
            <criterion comment="ofa-2.6.32-300.39.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130724"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130704"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130803"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130463"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130442"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130698"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130580"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129846"/>
            <criterion comment="ofa-2.6.32-300.39.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130040"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27628" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0998 -- kvm security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0998.html" ref_id="ELSA-2010-0998"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3881" ref_id="CVE-2010-3881"/>
        <description>[kvm-83-164.0.1.el5_5.30]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch to replace RHEL with OEL
- Added kvm-Introduce-oel-machine-type.patch so that OEL is a recognized VM

[kvm-83-164.el5_5.30]
- Revert the bz#661397 patches as they are not enough
  - kvm-kernel-Revert-KVM-VMX-Return-0-from-a-failed-VMREAD.patch [bz#661397]
  - kvm-kernel-Revert-KVM-Don-t-spin-on-virt-instruction-faults-dur.patch [bz#661397]
- Related: bz#661397
  (reboot(RB_AUTOBOOT) fails if kvm instance is running)
- kvm-kernel-KVM-fix-AMD-initial-TSC-offset-problems-additional-f.patch [bz#656984]
- Resolves: bz#656984
  (TSC offset of virtual machines is not initialized correctly by 'kvm_amd' kernel module.)

[kvm-83-164.el5_5.29]
- kvm-kernel-KVM-Don-t-spin-on-virt-instruction-faults-during-reb.patch [bz#661397]
- kvm-kernel-KVM-VMX-Return-0-from-a-failed-VMREAD.patch [bz#661397]
- Resolves: bz#661397
  (reboot(RB_AUTOBOOT) fails if kvm instance is running)

[kvm-83-164.el5_5.28]
- kvm-implement-dummy-PnP-support.patch [bz#659850]
- kvm-load-registers-after-restoring-pvclock-msrs.patch [bz#660239]
- Resolves: bz#659850
  (If VM boot seq. is set up as nc (PXE then disk) the VM is always stuck on trying to PXE boot)
- Resolves: bz#660239
  (clock drift when migrating a guest between mis-matched CPU clock speed)

[kvm-83-164.el5_5.27]
- kvm-kernel-KVM-fix-AMD-initial-TSC-offset-problems.patch [bz#656984]
- Resolves: bz#656984
  (TSC offset of virtual machines is not initialized correctly by 'kvm_amd' kernel module.)

[kvm-83-164.el5_5.26]
- Updated kversion to 2.6.18-194.26.1.el5 to match build root
- kvm-kernel-KVM-x86-fix-information-leak-to-userland.patch [bz#649832]
- Resolves: bz#649832
  (CVE-2010-3881 kvm: arch/x86/kvm/x86.c: reading uninitialized stack memory [5.5.z])
- CVE: CVE-2010-3881</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:06.293-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:23.997-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.724-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:53:40.963-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:53:40.963-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-164.0.1.el5_5.30" test_ref="oval:org.mitre.oval:tst:134473"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.0.1.el5_5.30" test_ref="oval:org.mitre.oval:tst:134685"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.0.1.el5_5.30" test_ref="oval:org.mitre.oval:tst:133906"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.0.1.el5_5.30" test_ref="oval:org.mitre.oval:tst:134860"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27623" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-0594-1 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0594-1.html" ref_id="ELSA-2013-0594-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3400" ref_id="CVE-2012-3400"/>
        <description>kernel [2.6.18-348.2.1.0.1] - [oprofile] x86, mm: Add __get_user_pages_fast()
          [orabug 14277030] - [oprofile] export __get_user_pages_fast() function [orabug 14277030] -
          [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030] - [oprofile]
          oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030] - [oprofile] oprofile: i386
          add get_user_pages_fast support [orabug 14277030] - [kernel] Initialize the local
          uninitialized variable stats. [orabug 14051367] - [fs] JBD:make jbd support 512B blocks
          correctly for ocfs2. [orabug 13477763] - [x86 ] fix fpu context corrupt when preempt in
          signal context [orabug 14038272] - [mm] fix hugetlb page leak (Dave McCracken) [orabug
          12375075] - fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan) -
          [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan) - [x86]
          Fix lvt0 reset when hvm boot up with noapic param - [scsi] remove printk's when doing I/O
          to a dead device (John Sobecki, Chris Mason) [orabug 12342275] - [char] ipmi: Fix IPMI
          errors due to timing problems (Joe Jin) [orabug 12561346] - [scsi] Fix race when removing
          SCSI devices (Joe Jin) [orabug 12404566] - [net] net: Redo the broken redhat netconsole
          over bonding (Tina Yang) [orabug 12740042] - [fs] nfs: Fix __put_nfs_open_context() NULL
          pointer panic (Joe Jin) [orabug 12687646] - fix filp_close() race (Joe Jin) [orabug
          10335998] - make xenkbd.abs_pointer=1 by default [orabug 67188919] - [xen] check to see if
          hypervisor supports memory reservation change (Chuck Anderson) [orabug 7556514] - [net]
          Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki) [orabug
          10315433] - [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258] -
          [mm] Patch shrink_zone to yield during severe mempressure events, avoiding hangs and
          evictions (John Sobecki,Chris Mason) [orabug 6086839] - [mm] Enhance shrink_zone patch
          allow full swap utilization, and also be NUMA-aware (John Sobecki,Chris Mason,Herbert van
          den Bergh) [orabug 9245919] - fix aacraid not to reset during kexec (Joe Jin) [orabug
          8516042] - [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
          [orabug 9107465] - [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
          [orabug 9764220] - Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615] -
          fix overcommit memory to use percpu_counter for (KOSAKI Motohiro, Guru Anbalagane) [orabug
          6124033] - [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208] - [ib] fix
          memory corruption (Andy Grover) [orabug 9972346] - [usb] USB: fix __must_check warnings in
          drivers/usb/core/ (Junxiao Bi) [orabug 14795203] - [usb] usbcore: fix endpoint device
          creation (Junxiao Bi) [orabug 14795203] - [usb] usbcore: fix refcount bug in endpoint
          removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:57.974-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:22.743-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.051-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35884 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:36.801-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:26.682-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130075"/>
          <criterion comment="ocfs2-2.6.18-348.2.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129679"/>
          <criterion comment="oracleasm-2.6.18-348.2.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130110"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129807"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129889"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130058"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130002"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129753"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130140"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129714"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130111"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129505"/>
          <criterion comment="ocfs2-2.6.18-348.2.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130091"/>
          <criterion comment="ocfs2-2.6.18-348.2.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129990"/>
          <criterion comment="ocfs2-2.6.18-348.2.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130003"/>
          <criterion comment="oracleasm-2.6.18-348.2.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129829"/>
          <criterion comment="oracleasm-2.6.18-348.2.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130039"/>
          <criterion comment="oracleasm-2.6.18-348.2.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130028"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27622" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2520 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2520.html" ref_id="ELSA-2013-2520"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6546" ref_id="CVE-2012-6546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1796" ref_id="CVE-2013-1796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6537" ref_id="CVE-2012-6537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0309" ref_id="CVE-2013-0309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0310" ref_id="CVE-2013-0310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1792" ref_id="CVE-2013-1792"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1798" ref_id="CVE-2013-1798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" ref_id="CVE-2013-0871"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1774" ref_id="CVE-2013-1774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6547" ref_id="CVE-2012-6547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5517" ref_id="CVE-2012-5517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0349" ref_id="CVE-2013-0349"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1827" ref_id="CVE-2013-1827"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4508" ref_id="CVE-2012-4508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1826" ref_id="CVE-2013-1826"/>
        <description>[2.6.32-400.26.2] - mm/hotplug: correctly add new zone to all other nodes' zone
          lists (Jiang Liu) [Orabug: 16603569] {CVE-2012-5517} - ptrace: ptrace_resume() shouldn't
          wake up !TASK_TRACED thread (Oleg Nesterov) [Orabug: 16405868] {CVE-2013-0871} - ptrace:
          ensure arch_ptrace/ptrace_request can never race with SIGKILL (Oleg Nesterov) [Orabug:
          16405868] {CVE-2013-0871} - ptrace: introduce signal_wake_up_state() and
          ptrace_signal_wake_up() (Oleg Nesterov) [Orabug: 16405868] {CVE-2013-0871} - Bluetooth:
          Fix incorrect strncpy() in hidp_setup_hid() (Anderson Lizardo) [Orabug: 16711062]
          {CVE-2013-0349} - dccp: check ccid before dereferencing (Mathias Krause) [Orabug:
          16711040] {CVE-2013-1827} - USB: io_ti: Fix NULL dereference in chase_port() (Wolfgang
          Frisch) [Orabug: 16425435] {CVE-2013-1774} - keys: fix race with concurrent
          install_user_keyrings() (David Howells) [Orabug: 16493369] {CVE-2013-1792} - KVM: Fix
          bounds checking in ioapic indirect register reads (CVE-2013-1798) (Andy Honig) [Orabug:
          16710937] {CVE-2013-1798} - KVM: x86: fix for buffer overflow in handling of
          MSR_KVM_SYSTEM_TIME (CVE-2013-1796) (Jerry Snitselaar) [Orabug: 16710794] {CVE-2013-1796}
          - net/tun: fix ioctl() based info leaks (Mathias Krause) [Orabug: 16675501]
          {CVE-2012-6547} - atm: fix info leak via getsockname() (Mathias Krause) [Orabug: 16675501]
          {CVE-2012-6546} - atm: fix info leak in getsockopt(SO_ATMPVC) (Mathias Krause) [Orabug:
          16675501] {CVE-2012-6546} - xfrm_user: fix info leak in copy_to_user_tmpl() (Mathias
          Krause) [Orabug: 16675501] {CVE-2012-6537} - xfrm_user: fix info leak in
          copy_to_user_policy() (Mathias Krause) [Orabug: 16675501] {CVE-2012-6537} - xfrm_user: fix
          info leak in copy_to_user_state() (Mathias Krause) [Orabug: 16675501] {CVE-2013-6537} -
          xfrm_user: return error pointer instead of NULL #2 (Mathias Krause) [Orabug: 16675501]
          {CVE-2013-1826} - xfrm_user: return error pointer instead of NULL (Mathias Krause)
          [Orabug: 16675501] {CVE-2013-1826}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:37.975-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:22.353-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:27.808-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:129531 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:41.097-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:25.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129044"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129375"/>
            <criterion comment="ofa-2.6.32-400.26.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129677"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129704"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129579"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129166"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129236"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129675"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129449"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129441"/>
            <criterion comment="ofa-2.6.32-400.26.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129225"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129537"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129531"/>
            <criterion comment="ofa-2.6.32-400.26.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129461"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129292"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129605"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129684"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129658"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129479"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129663"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129708"/>
            <criterion comment="ofa-2.6.32-400.26.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27619" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0123 -- OpenIPMI security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>OpenIPMI</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0123.html" ref_id="ELSA-2013-0123"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4339" ref_id="CVE-2011-4339"/>
        <description>[2.0.16-16.el5]

- ipmitool: fix ipmi command retry shifts replies (#863310)



[2.0.16-15.el5]

- ipmitool: added -b, -B, -l and -T options to ipmitool man page

  (#846596)

- ipmitool: fixed man page documentation for delloem setled command

  (#797050)



[2.0.16-14.el5]

- ipmitool: fixed wrong permissions on ipmievd.pid (#834190)



[2.0.16-13.el5]

- ipmitool: updated delloem commands (#797050)

- ipmitool: fixed exit code of 'ipmitool -o list' command (#740780)

- ipmitool: disabled automatic bridging of SDR readings to IPMB

  in verbose mode (#749796)

- ipmitool: fixed reporting of usage of various delloem subcommands

  (#658762)

- added path to /sbin to lsmod and modprobe (#829705)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:51.257-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:21.833-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:27.512-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:20:45.555-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:20:45.555-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="OpenIPMI is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:130652"/>
          <criterion comment="OpenIPMI-devel is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:130622"/>
          <criterion comment="OpenIPMI-gui is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:130276"/>
          <criterion comment="OpenIPMI-libs is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:130644"/>
          <criterion comment="OpenIPMI-perl is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:130468"/>
          <criterion comment="OpenIPMI-python is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:130471"/>
          <criterion comment="OpenIPMI-tools is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:130608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27618" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0646 -- pidgin security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0646.html" ref_id="ELSA-2013-0646"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0272" ref_id="CVE-2013-0272"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0273" ref_id="CVE-2013-0273"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0274" ref_id="CVE-2013-0274"/>
        <description>[2.7.9-10.el6_4.1]
- Fix spec file for disttag

[2.7.9-10.el6]
- Add patch for CVE-2013-0274 (RH bug #910653).

[2.7.9-9.el6]
- Add patch for CVE-2013-0273 (RH bug #910653).

[2.7.9-8.el6]
- Add patch for CVE-2013-0272 (RH bug #910653).

[2.7.9-7.el6]
- Add patch for CVE-2011-2485 (RH bug #837562).

[2.7.9-6.el6]
- Add patch for CVE-2012-1178 (RH bug #837560).
- Add patch for CVE-2012-2318 (RH bug #837560).
- Add patch for CVE-2012-3374 (RH bug #837560).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:39.707-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:21.325-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:27.201-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:31:37.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:31:37.713-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pidgin is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129886"/>
            <criterion comment="finch is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129905"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129752"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129922"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129324"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129692"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129625"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129438"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:128962"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pidgin is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129810"/>
            <criterion comment="finch is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129915"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129920"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129826"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129865"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129938"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129800"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129365"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129655"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27616" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0747 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0747.html" ref_id="ELSA-2013-0747"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0231" ref_id="CVE-2013-0231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1826" ref_id="CVE-2013-1826"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" ref_id="CVE-2012-6542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6546" ref_id="CVE-2012-6546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6547" ref_id="CVE-2012-6547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6537" ref_id="CVE-2012-6537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0216" ref_id="CVE-2013-0216"/>
        <description>kernel
[2.6.18-348.4.1]
- [virt] xen-netback: backports (Andrew Jones) [910884 910885] {CVE-2013-0216}
- [virt] xen-netback: netif_schedulable should take a netif (Andrew Jones) [910884 910885] {CVE-2013-0216}
- [virt] pciback: rate limit error mess from pciback_enable_msi() (Igor Mammedov) [910876 910877] {CVE-2013-0231}
- [net] be2net: remove BUG_ON() in be_mcc_compl_is_new() (Ivan Vecera) [923910 907524]
- [net] ipv4: Update MTU to all related cache entries (Amerigo Wang) [923353 905190]
- [net] annotate rt_hash_code() users (Amerigo Wang) [923353 905190]
- [net] xfrm_user: fix info leak in copy_to_user_state() (Thomas Graf) [922426 922427] {CVE-2012-6537}
- [net] xfrm_user: fix info leak in copy_to_user_policy() (Thomas Graf) [922426 922427] {CVE-2012-6537}
- [net] xfrm_user: fix info leak in copy_to_user_tmpl() (Thomas Graf) [922426 922427] {CVE-2012-6537}
- [net] atm: fix info leak in getsockopt(SO_ATMPVC) (Thomas Graf) [922384 922385] {CVE-2012-6546}
- [net] atm: fix info leak via getsockname() (Thomas Graf) [922384 922385] {CVE-2012-6546}
- [net] tun: fix ioctl() based info leaks (Thomas Graf) [922348 922349] {CVE-2012-6547}
- [net] llc, zero sockaddr_llc struct (Thomas Graf) [922327 922329] {CVE-2012-6542}
- [net] llc: fix info leak via getsockname() (Thomas Graf) [922327 922329] {CVE-2012-6542}
- [net] xfrm_user: return error pointer instead of NULL (Thomas Graf) [919386 919387] {CVE-2013-1826}
- [net] ixgbevf: allocate room for mailbox MSI-X interrupt's name (Laszlo Ersek) [924134 862862]
- [fs] knfsd: allow nfsd READDIR to return 64bit cookies (Niels de Vos) [924087 918952]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:40.956-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:20.914-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:26.836-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:43:25.171-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:43:25.171-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129599"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.4.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129490"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.4.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129638"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129676"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129506"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129756"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129197"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129511"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129584"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129670"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129154"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:129440"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.4.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129178"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.4.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129740"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.4.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129729"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.4.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129631"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.4.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128794"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.4.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27615" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0046 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0046.html" ref_id="ELSA-2010-0046"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3889" ref_id="CVE-2009-3889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3939" ref_id="CVE-2009-3939"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4020" ref_id="CVE-2009-4020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4021" ref_id="CVE-2009-4021"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4138" ref_id="CVE-2009-4138"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4141" ref_id="CVE-2009-4141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4272" ref_id="CVE-2009-4272"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2910" ref_id="CVE-2009-2910"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3080" ref_id="CVE-2009-3080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3556" ref_id="CVE-2009-3556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6304" ref_id="CVE-2006-6304"/>
        <description>[2.6.18-164.11.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb ( John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN  [orabug 7689332]
- [NET] Add xen pv/bonding  netconsole support (Tina yang) [orabug 6993043]
  [bz 7258]
- [MM] shrink zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- FP register state is corrupted during the handling a SIGSEGV (Chuck Anderson)
  [orabug 7708133]

[2.6.18-164.11.1.el5]
- [firewire] ohci: handle receive packets with zero data (Jay Fenlason) [547241 547242] {CVE-2009-4138}
- [x86] sanity check for AMD northbridges (Andrew Jones) [549905 547518]
- [x86_64] disable vsyscall in kvm guests (Glauber Costa) [550968 542612]
- [fs] ext3: replace lock_super with explicit resize lock (Eric Sandeen) [549908 525100]
- [fs] respect flag in do_coredump (Danny Feng) [544188 544189] {CVE-2009-4036}
- [gfs2] make O_APPEND behave as expected (Steven Whitehouse) [547521 544342]
- [fs] hfs: fix a potential buffer overflow (Amerigo Wang) [540740 540741] {CVE-2009-4020}
- [fuse] prevent fuse_put_request on invalid pointer (Danny Feng) [538736 538737] {CVE-2009-4021}
- [mm] call vfs_check_frozen after unlocking the spinlock (Amerigo Wang) [548370 541956]
- [infiniband] init neigh->dgid.raw on bonding events (Doug Ledford) [543448 538067]
- [scsi] gdth: prevent negative offsets in ioctl (Amerigo Wang) [539420 539421] {CVE-2009-3080}
- [fs] gfs2: fix glock ref count issues (Steven Whitehouse) [544978 539240]
- [net] call cond_resched in rt_run_flush (Amerigo Wang) [547530 517588]
- [scsi] megaraid: fix sas permissions in sysfs (Casey Dahlin) [537312 537313] {CVE-2009-3889 CVE-2009-3939}
- [ia64] kdump: restore registers in the stack on init (Takao Indoh ) [542582 515753]
- [x86] kvm: don't ask HV for tsc khz if not using kvmclock (Glauber Costa ) [537027 531268]
- [net] sched: fix panic in bnx2_poll_work (John Feeney ) [539686 526481]
- [x86_64] fix 32-bit process register leak (Amerigo Wang ) [526797 526798]
- [cpufreq] add option to avoid smi while calibrating (Matthew Garrett ) [537343 513649]
- [kvm] use upstream kvm_get_tsc_khz (Glauber Costa ) [540896 531025]
- [net] fix unbalance rtnl locking in rt_secret_reschedule (Neil Horman ) [549907 510067]
- [net] r8169: imporved rx length check errors (Neil Horman ) [552913 552438]
- [scsi] lpfc: fix FC ports offlined during target controller faults (Rob Evers ) [549906 516541]
- [net] emergency route cache flushing fixes (Thomas Graf ) [545662 545663] {CVE-2009-4272}
- [fs] fasync: split 'fasync_helper()' into separate add/remove functions (Danny Feng ) [548656 548657] {CVE-2009-4141}
- [scsi] qla2xxx: NPIV vport management pseudofiles are world writable (Tom Coughlan ) [537317 537318] {CVE-2009-3556}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:00.927-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:19.635-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:26.004-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:04:25.981-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:04:25.981-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135310"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.11.1.0.1.el5-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:134724"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.11.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135303"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135180"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134663"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134912"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134764"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134922"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135261"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134336"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134381"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134874"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.11.1.0.1.el5PAE-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135276"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.11.1.0.1.el5debug-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:134947"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.11.1.0.1.el5xen-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135267"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.11.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134933"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.11.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134993"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.11.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135288"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27613" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0981 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0981.html" ref_id="ELSA-2013-0981"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1682" ref_id="CVE-2013-1682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1684" ref_id="CVE-2013-1684"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1685" ref_id="CVE-2013-1685"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1686" ref_id="CVE-2013-1686"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1687" ref_id="CVE-2013-1687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1690" ref_id="CVE-2013-1690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1692" ref_id="CVE-2013-1692"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1693" ref_id="CVE-2013-1693"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1694" ref_id="CVE-2013-1694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1697" ref_id="CVE-2013-1697"/>
        <description>firefox
[17.0.7-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.7-1]
- Update to 17.0.7 ESR

xulrunner
[17.0.7-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.7-1]
- Update to 17.0.7 ESR

[17.0.6-5]
- Added workaround for rhbz#973721 - fixing problem with installation
  of  some addons

[17.0.6-4]
- Added a workaround for rhbz#961687 - Prelink throws message
  'Cannot safely convert .rel.dyn' section from REL to RELA'

[17.0.6-3]
- Added patch for aliasing issues (mozbz#821502)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:18.416-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:19.093-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:25.541-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:10:10.395-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:10:10.395-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129431"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129405"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128895"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128971"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129186"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129167"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27611" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0883 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0883.html" ref_id="ELSA-2013-0883"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2116" ref_id="CVE-2013-2116"/>
        <description>[2.8.5-10.2]
- fix CVE-2013-2116 - fix DoS regression in CVE-2013-1619
  upstream patch (#966754)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:24.608-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:18.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:25.339-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:19:57.367-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:19:57.367-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:129491"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:129350"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:129483"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129332"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129242"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129319"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129463"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27609" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0699 -- openssl security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0699.html" ref_id="ELSA-2012-0699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2333" ref_id="CVE-2012-2333"/>
        <description>[1.0.0-20.5]
- fix for CVE-2012-2333 - improper checking for record length in DTLS (#820686)
- properly initialize tkeylen in the CVE-2012-0884 fix</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:09.219-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:18.636-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:25.149-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:35:31.480-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:35:31.480-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:132098"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:131997"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:131901"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:132009"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:131652"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:131269"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:132115"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27607" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0145 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0145.html" ref_id="ELSA-2013-0145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0744" ref_id="CVE-2013-0744"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0746" ref_id="CVE-2013-0746"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0748" ref_id="CVE-2013-0748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0750" ref_id="CVE-2013-0750"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0753" ref_id="CVE-2013-0753"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0754" ref_id="CVE-2013-0754"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0758" ref_id="CVE-2013-0758"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0759" ref_id="CVE-2013-0759"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0762" ref_id="CVE-2013-0762"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0766" ref_id="CVE-2013-0766"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0767" ref_id="CVE-2013-0767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0769" ref_id="CVE-2013-0769"/>
        <description>[10.0.12-3.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[10.0.12-3]
- Update to 10.0.12 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:25.452-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:16.914-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:24.017-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:59:41.471-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:59:41.471-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129792"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130562"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27606" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0841 -- systemtap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0841.html" ref_id="ELSA-2011-0841"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1769" ref_id="CVE-2011-1769"/>
        <description>[1.3-4.1]
- bz702687 (patch)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:41.829-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:16.645-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:23.826-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:52:43.223-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:52:43.223-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="systemtap is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:133734"/>
          <criterion comment="systemtap-client is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:133806"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:133790"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:133848"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:133605"/>
          <criterion comment="systemtap-server is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:133272"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:133464"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27605" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0587 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0587.html" ref_id="ELSA-2013-0587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0166" ref_id="CVE-2013-0166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4929" ref_id="CVE-2012-4929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0169" ref_id="CVE-2013-0169"/>
        <description>[1.0.0-27.2]
- fix for CVE-2013-0169 - SSL/TLS CBC timing attack (#907589)
- fix for CVE-2013-0166 - DoS in OCSP signatures checking (#908052)
- enable compression only if explicitly asked for or OPENSSL_DEFAULT_ZLIB
  environment variable is set (fixes CVE-2012-4929 #857051)
- use __secure_getenv() everywhere instead of getenv() (#839735)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:50.662-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:16.246-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:23.578-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:32:12.519-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:32:12.519-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:130221"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:130232"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:129978"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:130167"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:129799"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:130172"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:129772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27603" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0942 -- krb5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0942.html" ref_id="ELSA-2013-0942"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2443" ref_id="CVE-2002-2443"/>
        <description>[1.10.3-10.3]
- pull up fix for UDP ping-pong flaw in kpasswd service (CVE-2002-2443,</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:34.864-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:15.174-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.773-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:28:17.500-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:28:17.500-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:128767"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:128623"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:129006"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:129313"/>
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:128925"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:129155"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129346"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129131"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129181"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129323"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:128864"/>
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129152"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129390"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27602" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2511 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2511.html" ref_id="ELSA-2013-2511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" ref_id="CVE-2013-0268"/>
        <description>[2.6.39-400.17.2]
- x86/msr: Add capabilities check (Alan Cox) [Orabug: 16405007] {CVE-2013-0268}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:55.420-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:14.983-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.633-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129783"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129743"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130034"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130029"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129508"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129737"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129878"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130037"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129088"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129263"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129648"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129815"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27596" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2038 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2038.html" ref_id="ELSA-2012-2038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.32-300.37.1.] - sfc: Replace some literal constants with
          EFX_PAGE_SIZE/EFX_BUF_SIZE (Ben Hutchings) [Orabug: 14769994] - CVE-2012-3412 sfc: Fix
          maximum number of TSO segments and minimum TX queue size (Ben Hutchings) [Orabug:
          14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:45.970-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:13.757-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:21.796-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27596 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:35.604-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:25.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130966"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130701"/>
            <criterion comment="ofa-2.6.32-300.37.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130805"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:131059"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130989"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:131052"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130639"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:131021"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130170"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130798"/>
            <criterion comment="ofa-2.6.32-300.37.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130738"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:130839"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131072"/>
            <criterion comment="ofa-2.6.32-300.37.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130884"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131118"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:130682"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131041"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131070"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131150"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:130903"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130689"/>
            <criterion comment="ofa-2.6.32-300.37.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130914"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27594" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0745 -- python security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0745.html" ref_id="ELSA-2012-0745"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4940" ref_id="CVE-2011-4940"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4944" ref_id="CVE-2011-4944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1150" ref_id="CVE-2012-1150"/>
        <description>[2.4.3-46.el5_8.2]
- if hash randomization is enabled, also enable it within pyexpat
Resolves: CVE-2012-0876

[2.4.3-46.el5_8.1]
- distutils.commands.register: create ~/.pypirc securely
Resolves: CVE-2011-4944
- send encoding in SimpleHTTPServer.list_directory to protect IE7 against
potential XSS attacks
Resolves: CVE-2011-4940
- oCERT-2011-003: add -R command-line option and PYTHONHASHSEED environment
variable, to provide an opt-in way to protect against denial of service
attacks due to hash collisions within the dict and set types
Resolves: CVE-2012-1150</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:10.831-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:13.346-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:21.382-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:19:13.536-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:19:13.536-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:131857"/>
          <criterion comment="python-devel is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:131679"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:131965"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:131890"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:131966"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27592" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0092 -- php53 security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0092.html" ref_id="ELSA-2012-0092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0830" ref_id="CVE-2012-0830"/>
        <description>[5.3.3-1.6]
- add security fix for CVE-2012-0830 (#786757)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:25.472-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:12.830-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:20.959-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:21:47.986-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:21:47.986-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132683"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132498"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132768"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132612"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132675"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132729"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:131827"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132731"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132565"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132765"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132787"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132295"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132536"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132075"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132732"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132767"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:131821"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132391"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:132448"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:131843"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:131878"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27591" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0730 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0730.html" ref_id="ELSA-2012-0730"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1711" ref_id="CVE-2012-1711"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1713" ref_id="CVE-2012-1713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1716" ref_id="CVE-2012-1716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1717" ref_id="CVE-2012-1717"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1718" ref_id="CVE-2012-1718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1719" ref_id="CVE-2012-1719"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1723" ref_id="CVE-2012-1723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1724" ref_id="CVE-2012-1724"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1725" ref_id="CVE-2012-1725"/>
        <description>[1.6.0.0-1.27.1.10.8.0.1.el5_8]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.27.1.10.8]
- Modified patch3, java-1.6.0-openjdk-java-access-bridge-security.patch:
  - com.sun.org.apache.xerces.internal.utils.,com.sun.org.apache.xalan.internal.utils.
  - packages added also to package.definition
- Resolves: rhbz#828749

[1:1.6.0.0-1.26.1.10.8]
- Updated to IcedTea6 1.10.8
- Modified patch3, java-1.6.0-openjdk-java-access-bridge-security.patch:
  - com.sun.org.apache.xerces.internal.utils.,com.sun.org.apache.xalan.internal.utils.
  - packages added to patch
- Resolves: rhbz#828749</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:14.154-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:12.679-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:20.793-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:38:22.540-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:38:22.540-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.27.1.10.8.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131945"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.27.1.10.8.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131973"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.27.1.10.8.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131980"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.27.1.10.8.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131781"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.27.1.10.8.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27588" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0542 -- openldap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0542.html" ref_id="ELSA-2010-0542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0211" ref_id="CVE-2010-0211"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0212" ref_id="CVE-2010-0212"/>
        <description>[2.3.43-12.1]
- fixed segfault issues in modrdn (#606375)
- added patch handling null char in TLS to compat package
  (#606375, patch backported by Jan Vcelak &lt;jvcelak@redhat.com>)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:49.631-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:12.012-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:20.167-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:27:52.964-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:27:52.964-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:134979"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:135053"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:134829"/>
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:134757"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:135029"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:135051"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5_5.1" test_ref="oval:org.mitre.oval:tst:134751"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27587" version="5" class="patch">
      <metadata>
        <title>ELSA-2010-2008 -- Unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-firmware</product>
          <product>kernel-headers</product>
          <product>ofa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-2008.html" ref_id="ELSA-2010-2008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2942" ref_id="CVE-2010-2942"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2943" ref_id="CVE-2010-2943"/>
        <description>[2.6.32-100.20.1.el5] - [fs] xfs: return inode fork offset in bulkstat for fsr
          (Dave Chinner) - [fs] xfs: always use iget in bulkstat (Dave Chinner) {CVE-2010-2943} -
          [fs] xfs: validate untrusted inode numbers during lookup (Dave Chinner) {CVE-2 010-2943} -
          [fs] xfs: rename XFS_IGET_BULKSTAT to XFS_IGET_UNTRUSTED (Dave Chinner) {CVE-2 010-2943} -
          [net] net sched: fix some kernel memory leaks (Eric Dumazet) {CVE-2010-2942} - [fs] ocfs2:
          Don't walk off the end of fast symlinks (Joel Becker)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:03.589-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:11.662-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.961-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:134962 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:38.902-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:24.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-100.20.1.el5" test_ref="oval:org.mitre.oval:tst:134831"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-100.20.1.el5" test_ref="oval:org.mitre.oval:tst:134605"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-100.20.1.el5" test_ref="oval:org.mitre.oval:tst:133982"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-100.20.1.el5" test_ref="oval:org.mitre.oval:tst:134779"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-100.20.1.el5" test_ref="oval:org.mitre.oval:tst:133983"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-100.20.1.el5" test_ref="oval:org.mitre.oval:tst:134614"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-100.20.1.el5" test_ref="oval:org.mitre.oval:tst:134975"/>
          <criterion comment="ofa-2.6.32-100.20.1.el5 is earlier than 0:1.5.1-4.0.20" test_ref="oval:org.mitre.oval:tst:134962"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27585" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0394 -- conga security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0394.html" ref_id="ELSA-2011-0394"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0720" ref_id="CVE-2011-0720"/>
        <description>[0.12.2-24.0.1.el5_6.1]
- Added conga-enterprise.patch
- Added conga-enterprise-Carthage.patch to support OEL5
- Recreated Data.fs  in luci_db.tar.gz
- Replaced redhat logo image in conga-0.12.2.tar.gz

[0.12.2-24.1]
- Fix bz680515 (CVE-2011-0720 plone: unauthorized remote administrative access)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:10.683-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:11.057-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.716-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:19:49.375-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:19:49.375-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="conga is earlier than 0:0.12.2-24.0.1.el5_6.1" test_ref="oval:org.mitre.oval:tst:133459"/>
          <criterion comment="luci is earlier than 0:0.12.2-24.0.1.el5_6.1" test_ref="oval:org.mitre.oval:tst:133620"/>
          <criterion comment="ricci is earlier than 0:0.12.2-24.0.1.el5_6.1" test_ref="oval:org.mitre.oval:tst:133937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27584" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0270 -- jakarta-commons-httpclient security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0270.html" ref_id="ELSA-2013-0270"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5783" ref_id="CVE-2012-5783"/>
        <description>[1:3.1-0.7]
- Add missing connection hostname check against X.509 certificate name
- Resolves: CVE-2012-5783</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:33.007-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:10.761-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.519-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:27:03.954-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:27:03.954-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130011"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130060"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130063"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130346"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130302"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130393"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130219"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27582" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0958 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0958.html" ref_id="ELSA-2013-0958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1500" ref_id="CVE-2013-1500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1571" ref_id="CVE-2013-1571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2407" ref_id="CVE-2013-2407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2412" ref_id="CVE-2013-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2443" ref_id="CVE-2013-2443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2444" ref_id="CVE-2013-2444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2445" ref_id="CVE-2013-2445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2446" ref_id="CVE-2013-2446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2447" ref_id="CVE-2013-2447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2448" ref_id="CVE-2013-2448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2449" ref_id="CVE-2013-2449"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2450" ref_id="CVE-2013-2450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2452" ref_id="CVE-2013-2452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2453" ref_id="CVE-2013-2453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2454" ref_id="CVE-2013-2454"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2455" ref_id="CVE-2013-2455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2456" ref_id="CVE-2013-2456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2457" ref_id="CVE-2013-2457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2458" ref_id="CVE-2013-2458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2459" ref_id="CVE-2013-2459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2460" ref_id="CVE-2013-2460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2461" ref_id="CVE-2013-2461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2463" ref_id="CVE-2013-2463"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2465" ref_id="CVE-2013-2465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2469" ref_id="CVE-2013-2469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2470" ref_id="CVE-2013-2470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2471" ref_id="CVE-2013-2471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2472" ref_id="CVE-2013-2472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2473" ref_id="CVE-2013-2473"/>
        <description>[1.7.0.25-2.3.10.4.0.1.el5_9]
- Add oracle-enterprise.patch
- Fix DISTRO_NAME to 'Enterprise Linux'

[1.7.0.25-2.3.10.4.el5]
- updated to newer IcedTea7-forest 2.3.10 with 8010118 fix
- removed upstreamed patch1000 MBeanFix.patch
- Resolves: rhbz#973117

[1.7.0.25-2.3.10.3.el5]
- reverted fix for license files owning
- Resolves: rhbz#973117

[1.7.0.25-2.3.10.2.el5]
- added patch1000 MBeanFix.patch to fix regressions caused by security patches
- Resolves: rhbz#973117

[1.7.0.25-2.3.10.1.el6]
- build bumped to 25
- Resolves: rhbz#973117

[1.7.0.19-2.3.10.0.el5]
- Updated to latest IcedTea7-forest 2.3.10
- patch 107 renamed to 500 for cosmetic purposes
- Added fix for RH857717, owned /etc/.java/ and /etc/.java/.systemPrefs
- Resolves: rhbz#973117

[1.7.0.19-2.3.10.0.el5]
- Updated to latest IcedTea7-forest 2.3.10
- Resolves: rhbz#973117</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:26.720-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:10.268-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.249-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:07:19.727-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:07:19.727-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.25-2.3.10.4.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129355"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.25-2.3.10.4.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129402"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.25-2.3.10.4.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129294"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.25-2.3.10.4.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129408"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.25-2.3.10.4.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27581" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0588 -- gnutls security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0588.html" ref_id="ELSA-2013-0588"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1619" ref_id="CVE-2013-1619"/>
        <description>[2.8.5-10.1]
- fix CVE-2013-1619 - fix TLS-CBC timing attack (#908238)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:37.103-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:09.969-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.083-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:31:21.784-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:31:21.784-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:129969"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:129816"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:129275"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129289"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129845"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:130053"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129979"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27580" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0153 -- sos security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0153.html" ref_id="ELSA-2012-0153"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4083" ref_id="CVE-2011-4083"/>
        <description>[1.7-9.62.0.1.el5]
- add patch to remove all sysrq echo commands from sysreport.legacy
  (John Sobecki) [orabug 11061754]
- comment out rh-upload-core and README.rh-upload-core in specfile</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:03.503-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:09.687-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:18.917-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:11:47.542-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:11:47.542-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sos is earlier than 0:1.7-9.62.0.1.el5" test_ref="oval:org.mitre.oval:tst:132619"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27577" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0580 -- cups security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0580.html" ref_id="ELSA-2013-0580"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5519" ref_id="CVE-2012-5519"/>
        <description>[1:1.4.2-50:.4]
- Added BrowseLDAPCACertFile and PrintcapGUI to restricted options
  list.

[1:1.4.2-50:.3]
- Fix for CVE-2012-5519 patch: handle blacklisted lines that have no
  value part gracefully.

[1:1.4.2-50:.2]
- Added documentation for new CVE-2012-5519 option.

[1:1.4.2-50:.1]
- Applied patch to fix CVE-2012-5519 (privilege escalation for users
  in SystemGroup or with equivalent polkit permission).  This prevents
  HTTP PUT requests with paths under /admin/conf/ other than that for
  cupsd.conf, and also prevents such requests altering certain
  configuration directives such as PageLog and FileDevice (bug #875898).

[1:1.4.2-50]
- Fixed LDAP browsing issues (bug #870386).

[1:1.4.2-49]
- Avoid 'forbidden' error when moving job between queues via web UI
  (bug #834445).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:45.028-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:08.947-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:18.416-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:59:36.033-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:59:36.033-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:130242"/>
            <criterion comment="cups-devel is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:130268"/>
            <criterion comment="cups-libs is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:130183"/>
            <criterion comment="cups-lpd is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:129592"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130033"/>
            <criterion comment="cups-devel is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130233"/>
            <criterion comment="cups-libs is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:129667"/>
            <criterion comment="cups-lpd is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130027"/>
            <criterion comment="cups-php is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130253"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27573" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0250 -- elinks security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>elinks</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0250.html" ref_id="ELSA-2013-0250"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4545" ref_id="CVE-2012-4545"/>
        <description>[0.12-0.21.pre5]
- do not delegate GSSAPI credentials (CVE-2012-4545)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:46.701-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:07.881-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:17.765-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:52:14.207-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:52:14.207-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:129956"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:130340"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27572" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0603 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0603.html" ref_id="ELSA-2013-0603"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0809" ref_id="CVE-2013-0809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1493" ref_id="CVE-2013-1493"/>
        <description>[1.7.0.9-2.3.8.0.0.1.el5_9]
- Add oracle-enterprise.patch
- Fix DISTRO_NAME to 'Enterprise Linux'

[1.7.0.9-2.3.8.0.el5_9]
- Updated to icedtea7-forest-2.3
- Resolves: rhbz#917181</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:57.129-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:07.694-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:17.678-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:40:52.191-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:40:52.191-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.8.0.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129547"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.8.0.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130080"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.8.0.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129818"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.8.0.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129459"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.8.0.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27571" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0168 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0168.html" ref_id="ELSA-2013-0168"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1568" ref_id="CVE-2012-1568"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4444" ref_id="CVE-2012-4444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5515" ref_id="CVE-2012-5515"/>
        <description>kernel
[2.6.18-348.1.1]
- [pci] intel-iommu: reduce max num of domains supported (Don Dutile) [886876 885125]
- [fs] gfs2: Fix leak of cached directory hash table (Steven Whitehouse) [886124 831330]
- [x86] mm: randomize SHLIB_BASE (Petr Matousek) [804953 804954] {CVE-2012-1568}
- [net] be2net: create RSS rings even in multi-channel configs (Ivan Vecera) [884702 878209]
- [net] tg3: Avoid dma read error (John Feeney) [885692 877474]
- [misc] Fix unsupported hardware message (Prarit Bhargava) [885063 876587]
- [net] ipv6: discard overlapping fragment (Jiri Pirko) [874837 874838] {CVE-2012-4444}
- [usb] Fix serial port reference counting on hotplug remove (Don Zickus) [885700 845447]
- [net] bridge: export its presence and fix bonding igmp reporting (Veaceslav Falico) [884742 843473]
- [fs] nfs: move wait for server->active from put_super to kill_sb (Jeff Layton) [884708 839839]
- [scsi] libfc: fix indefinite rport restart (Neil Horman) [884740 595184]
- [scsi] libfc: Retry a rejected PRLI request (Neil Horman) [884740 595184]
- [scsi] libfc: Fix remote port restart problem (Neil Horman) [884740 595184]
- [xen] memop: limit guest specified extent order (Laszlo Ersek) [878449 878450] {CVE-2012-5515}
- [xen] get bottom of EBDA from the multiboot data structure (Paolo Bonzini) [885062 881885]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:48.036-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:07.289-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:17.437-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:36:31.584-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:36:31.584-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:129788"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.1.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130575"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.1.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130115"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:130446"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:130131"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:130600"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:130495"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:129630"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:130362"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:130512"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:129652"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:130098"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.1.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129678"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.1.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130615"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.1.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130523"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.1.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130387"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.1.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130450"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.1.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27570" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0135 -- gtk2 security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gtk2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0135.html" ref_id="ELSA-2013-0135"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2370" ref_id="CVE-2012-2370"/>
        <description>[2.10.4-29]

- Improve patch to parse CUPS user lpoptions file to avoid crashes

  on s390 and ia64

  Resolves: #603809</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:29.046-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:07.068-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:17.163-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:08:05.392-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:08:05.392-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gtk2 is earlier than 0:2.10.4-29.el5" test_ref="oval:org.mitre.oval:tst:130584"/>
          <criterion comment="gtk2-devel is earlier than 0:2.10.4-29.el5" test_ref="oval:org.mitre.oval:tst:130699"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27568" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0815 -- httpd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0815.html" ref_id="ELSA-2013-0815"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4558" ref_id="CVE-2012-4558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1862" ref_id="CVE-2013-1862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3499" ref_id="CVE-2012-3499"/>
        <description>[2.2.15-28.0.1.el6_4]
- replace index.html with Oracle's index page oracle_index.html
  update vstring in specfile

[2.2.15-28]
- mod_rewrite: add security fix for CVE-2013-1862 (#953729)

[2.2.15-27]
- add security fixes for CVE-2012-3499, CVE-2012-4558 (#915883, #915884)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:46.665-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:06.163-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:16.790-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:17:40.410-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:17:40.410-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129685"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129593"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129524"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129474"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129561"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129661"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129600"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129643"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129014"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27565" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1235 -- kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1235.html" ref_id="ELSA-2012-1235"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3515" ref_id="CVE-2012-3515"/>
        <description>[83-249.0.1.el5_8.5]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch

[83-249.el5_8.5]
- kvm-console-bounds-check-whenever-changing-the-cursor-du-58.patch [bz#851255]
- CVE: CVE-2012-3515
- Resolves: bz#851255
  (EMBARGOED CVE-2012-3515 qemu/kvm: VT100 emulation vulnerability [rhel-5.8.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:21.873-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:05.089-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:16.290-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:26:03.573-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:26:03.573-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-249.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131198"/>
          <criterion comment="kmod-kvm is earlier than 0:83-249.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130657"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-249.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130389"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-249.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131292"/>
          <criterion comment="kvm-tools is earlier than 0:83-249.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131227"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27563" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0107 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0107.html" ref_id="ELSA-2012-0107"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0207" ref_id="CVE-2012-0207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3638" ref_id="CVE-2011-3638"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4127" ref_id="CVE-2011-4127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4086" ref_id="CVE-2011-4086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0028" ref_id="CVE-2012-0028"/>
        <description>This update fixes the following security issues:

* Using the SG_IO ioctl to issue SCSI requests to partitions or LVM volumes
resulted in the requests being passed to the underlying block device. If a
privileged user only had access to a single partition or LVM volume, they
could use this flaw to bypass those restrictions and gain read and write
access (and be able to issue other SCSI commands) to the entire block
device. Refer to Red Hat Knowledgebase article DOC-67874, linked to in the
References, for further details about this issue. (CVE-2011-4127,
Important)

* A flaw was found in the way the Linux kernel handled robust list pointers
of user-space held futexes across exec() calls. A local, unprivileged user
could use this flaw to cause a denial of service or, eventually, escalate
their privileges. (CVE-2012-0028, Important)

* A flaw was found in the Linux kernel in the way splitting two extents in
ext4_ext_convert_to_initialized() worked. A local, unprivileged user with
the ability to mount and unmount ext4 file systems could use this flaw to
cause a denial of service. (CVE-2011-3638, Moderate)

* A flaw was found in the way the Linux kernel's journal_unmap_buffer()
function handled buffer head states. On systems that have an ext4 file
system with a journal mounted, a local, unprivileged user could use this
flaw to cause a denial of service. (CVE-2011-4086, Moderate)

* A divide-by-zero flaw was found in the Linux kernel's igmp_heard_query()
function. An attacker able to send certain IGMP (Internet Group Management
Protocol) packets to a target system could use this flaw to cause a denial
of service. (CVE-2012-0207, Moderate)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:07.918-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:04.298-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:15.807-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:59:32.635-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:59:32.635-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132669"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.18.1.0.1.el5-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132688"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.18.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132624"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132526"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132777"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131850"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132236"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132423"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132453"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132785"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132784"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:132359"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.18.1.0.1.el5PAE-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132691"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.18.1.0.1.el5debug-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:131921"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-274.18.1.0.1.el5xen-1.4.9-1.el5" test_ref="oval:org.mitre.oval:tst:132604"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.18.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132398"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.18.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132490"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-274.18.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:132429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27562" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0272 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0272.html" ref_id="ELSA-2013-0272"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0775" ref_id="CVE-2013-0775"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0776" ref_id="CVE-2013-0776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0780" ref_id="CVE-2013-0780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0782" ref_id="CVE-2013-0782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0783" ref_id="CVE-2013-0783"/>
        <description>[17.0.3-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.3-1]
- Update to 17.0.3 ESR

[17.0.2-2]
- Update to 17.0.2 ESR

[17.0-2]
- Update to 17.0 ESR

[17.0b2-0.1]
- Update to 17.0b2

[17.0b1-0.1]
- Rebase to 17 beta 1</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:56.621-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:04.175-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:15.710-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:33:10.497-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:33:10.497-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130216"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27560" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0120 -- quota security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>quota</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0120.html" ref_id="ELSA-2013-0120"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3417" ref_id="CVE-2012-3417"/>
        <description>[1:3.13-8.0.1]

- Add ocfs2 support (Orabug: 14208111)



[1:3.13-8]

- Fix CVE-2012-3417 (incorrect use of tcp_wrappers) (Resolves: #841448)



[1:3.13-7]

- Fix parsing numeric arguments of setquota (Resolves: #831520)



[1:3.13-6]

- Do not use real domains in warnquota example (Resolves: #680429)

- Use /proc/mounts for mountpoint scanning (Resolves: #689822)

- Use rq_bsize to convert quotas transferred by RPC (bug #667360)

- Make RPC block factor dynamic (bug #667360)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:29.866-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:03.563-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:15.335-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:52:10.195-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:52:10.195-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="quota is earlier than 0:3.13-8.0.1.el5" test_ref="oval:org.mitre.oval:tst:129791"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27558" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0258 -- pam_krb5 security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pam_krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0258.html" ref_id="ELSA-2010-0258"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1384" ref_id="CVE-2009-1384"/>
        <description>[2.2.14-15]
- update backport for selecting which key to use for validation so that it
  prefers services with the local host name as the instance, from HEAD (more
  of #450776)

[2.2.14-14]
- backport the 'multiple_ccaches' option from HEAD, requiring that it
  be enabled to not immediately remove an old ccache when asked to create
  a new one (#463417)

[2.2.14-13]
- add patch to add the 'chpw_prompt' option, to allow the older behavior
  of attempting a password-change during authentication if libkrb5 detects
  an expired password, based on patch from Olivier Fourdan (#509092)

[2.2.14-12]
- dont vary the password prompt depending on whether or not the user exists
  or is known to the KDC (CVE-2009-1384, #505265)
- prefer using the 'host' service when verifying that a TGT isnt forged,
  from HEAD (#450776)

[2.2.14-11]
- dont enforce minimum_uid when no_user_check is also used, from
  HEAD (#490404)
- dont try to get password-changing creds with all of the flags set
  that we would request for a TGT (#489015)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:57.696-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:03.225-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:14.975-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:23:51.954-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:23:51.954-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="pam_krb5 is earlier than 0:2.2.14-15" test_ref="oval:org.mitre.oval:tst:134846"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27557" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1045 -- php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1045.html" ref_id="ELSA-2012-1045"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4153" ref_id="CVE-2011-4153"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0057" ref_id="CVE-2012-0057"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0789" ref_id="CVE-2012-0789"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1172" ref_id="CVE-2012-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2336" ref_id="CVE-2012-2336"/>
        <description>[5.1.6-39]
- fix issue in CVE-2012-0057 patch

[5.1.6-38]
- fix memory handling in CVE-2012-0789 patch

[5.1.6-37]
- add security fixes for CVE-2012-0057, CVE-2011-4153, CVE-2012-0789,
  CVE-2012-1172

[5.1.6-36]
- add security fix for CVE-2012-2336</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:24.069-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:03.074-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:14.712-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:48:16.013-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:48:16.013-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131402"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131297"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131651"/>
          <criterion comment="php-common is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131620"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131233"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131723"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131727"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131725"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:130796"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131703"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:130834"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131683"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131469"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131680"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131549"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131740"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131474"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131787"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:131663"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27555" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2523 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2523.html" ref_id="ELSA-2013-2523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4542" ref_id="CVE-2012-4542"/>
        <description>[2.6.39-400.23.1]
- Parallel mtrr init between cpus (Zhenzhong Duan) [Orabug: 16777774]
- Merge tag 'v2.6.39-400.21.1.16748891' of git://ca-git.us.oracle.com/linux-uek-2.6.39-ofed into uek-2.6.39-400 (Maxim Uvarov) [Orabug: 16748891]
- xen-blkfront: use a different scatterlist for each request (Roger Pau Monne)
- Fix EN driver to work with newer FWs based on latest mlx4_core (Yuval Shaia) [Orabug: 16748891]

[2.6.39-400.22.1]
- block: default SCSI command filter does not accomodate commands overlap across device classes (Jamie Iles) [Orabug: 16387137] {CVE-2012-4542}
- Merge tag 'v2.6.39-400.21.1#bug16684527' of git://ca-git.us.oracle.com/linux-joejin-public into uek-2.6.39-400_errata (Maxim Uvarov) [Orabug: 16684527]
- KVM: x86: Convert MSR_KVM_SYSTEM_TIME to use gfn_to_hva_cache functions (CVE-2013-1797) (Andy Honig) [Orabug: 16711660] {CVE-2013-1797}
- Bluetooth: Fix incorrect strncpy() in hidp_setup_hid() (Anderson Lizardo) [Orabug: 16711065] {CVE-2013-0349}
- USB: io_ti: Fix NULL dereference in chase_port() (Wolfgang Frisch) [Orabug: 16425358] {CVE-2013-1774}
- keys: fix race with concurrent install_user_keyrings() (David Howells) [Orabug: 16493354] {CVE-2013-1792}
- KVM: Fix bounds checking in ioapic indirect register reads (CVE-2013-1798) (Andy Honig) [Orabug: 16710951] {CVE-2013-1798}
- KVM: x86: fix for buffer overflow in handling of MSR_KVM_SYSTEM_TIME (CVE-2013-1796) (Andy Honig) [Orabug: 16710806] {CVE-2013-1796}
- tmpfs: fix use-after-free of mempolicy object (Greg Thelen) [Orabug: 16515833] {CVE-2013-1767}
- procfs: do not confuse jiffies with cputime64_t (Andreas Schwab) [Orabug: 16673925]
- procfs: do not overflow get_{idle,iowait}_time for nohz (Michal Hocko) [Orabug: 16673925]
- xen/evtchn: Handle VIRQ_TIMER before any other hardirq in event loop. (Keir Fraser) [Orabug: 16093126]
- Fix device removal NULL pointer dereference (Joe Jin) [Orabug: 16684527]
- put stricter guards on queue dead checks (James Bottomley) [Orabug: 16684527]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:42.829-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:02.466-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:14.088-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129253"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129386"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129494"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129344"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129462"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129422"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129653"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129649"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129619"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129437"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129639"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129562"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27554" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0827 -- openswan security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0827.html" ref_id="ELSA-2013-0827"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2053" ref_id="CVE-2013-2053"/>
        <description>[2.6.32-20]
Resolves: #960234 - CVE-2013-2053</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:51.991-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:02.280-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.953-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:45:04.378-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:45:04.378-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:129351"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:129306"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:129450"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:128914"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27551" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0275 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0275.html" ref_id="ELSA-2013-0275"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1485" ref_id="CVE-2013-1485"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1484" ref_id="CVE-2013-1484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1486" ref_id="CVE-2013-1486"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0169" ref_id="CVE-2013-0169"/>
        <description>[1.7.0.9-2.3.7.1.0.2.el6_3]
- Increase release number and rebuild.

[1.7.0.9-2.3.7.1.0.1.el6_3]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.7.1.el6_3]
- Updated main source tarball
- Resolves: rhbz#911529

[1.7.0.9-2.3.7.0.el6_3]
- Removed patch1000 sec-2013-02-01-8005615.patch
- Removed patch1001 sec-2013-02-01-8005615-sync_with_jdk7u.patch
- Removed patch1010 sec-2013-02-01-7201064.patch
- Removed testing
 - mauve was outdated and
 - jtreg was icedtea relict
- Updated  to icedtea 2.3.7
- Added java -Xshare:dump to post (see 513605) fo jitarchs
- Resolves: rhbz#911529</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:55.345-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:01.653-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.348-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:49:00.580-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:49:00.580-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130282"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129948"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130151"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129977"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130448"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130290"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130327"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130384"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130410"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130090"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27550" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2020 -- Unbreakable Enterprise kernel security and bugfix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2020.html" ref_id="ELSA-2012-2020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2123" ref_id="CVE-2012-2123"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2136" ref_id="CVE-2012-2136"/>
        <description>kernel-uek: [2.6.32-300.27.1.el6uek] - net: sock: validate data_len before
          allocating skb (Jason Wang) [Bugdb: 13966]{CVE-2012-2136} - fcaps: clear the same
          personality flags as suid when fcaps are used (Eric Paris) [Bugdb: 13966] {CVE-2012-2123}
          - Revert 'nfs: when attempting to open a directory, fall back on normal lookup (Todd
          Vierling) [Orabug 14141154] [2.6.32-300.26.1.el6uek] - mptsas: do not call __mptsas_probe
          in kthread (Maxim Uvarov) [Orabug: 14175509] - mm: check if any page in a pageblock is
          reserved before marking it MIGRATE_RESERVE (Maxim Uvarov) [Orabug: 14073214] - mm: reduce
          the amount of work done when updating min_free_kbytes (Mel Gorman) [Orabug: 14073214] -
          vmxnet3: Updated to el6-u2 (Guangyu Sun) [Orabug: 14027961] - xen: expose host uuid via
          sysfs. (Zhigang Wang) - sched: Fix cgroup movement of waking process (Daisuke Nishimura)
          [Orabug: 13946210] - sched: Fix cgroup movement of newly created process (Daisuke
          Nishimura) [Orabug: 13946210] - sched: Fix cgroup movement of forking process (Daisuke
          Nishimura) [Orabug: 13946210] - x86, boot: Wait for boot cpu to show up if nr_cpus limit
          is about to hit (Zhenzhong Duan) [Orabug: 13629087] - smp: Use nr_cpus= to set nr_cpu_ids
          early (Zhenzhong Duan) [Orabug: 13629087] - net: ipv4: relax AF_INET check in bind()
          (Maxim Uvarov) [Orabug: 14054411] ofa-2.6.32-300.27.1.el6uek: [1.5.1-4.0.58] - Add Patch
          158-169</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:38.809-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:01.334-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.137-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36582 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:38.710-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:23.976-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131839"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131914"/>
            <criterion comment="ofa-2.6.32-300.27.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131604"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131880"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131574"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131692"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131561"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131931"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:130973"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131822"/>
            <criterion comment="ofa-2.6.32-300.27.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131897"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131849"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131765"/>
            <criterion comment="ofa-2.6.32-300.27.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131319"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131936"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131865"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131797"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131934"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131520"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131482"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131852"/>
            <criterion comment="ofa-2.6.32-300.27.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131719"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27547" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1363 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1363.html" ref_id="ELSA-2012-1363"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5166" ref_id="CVE-2012-5166"/>
        <description>[32:9.8.2-0.10.rc1.5]
- fix CVE-2012-5166</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:29.441-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:00.809-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.888-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:51:51.886-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:51:51.886-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130730"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131081"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130950"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131033"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130920"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130711"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131055"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130760"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130220"/>
            <criterion comment="bind-chroot is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:131162"/>
            <criterion comment="bind-devel is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:131161"/>
            <criterion comment="bind-libs is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130877"/>
            <criterion comment="bind-sdb is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:131151"/>
            <criterion comment="bind-utils is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130196"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27545" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2525 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2525.html" ref_id="ELSA-2013-2525"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" ref_id="CVE-2012-6542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" ref_id="CVE-2013-1929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1860" ref_id="CVE-2013-1860"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1848" ref_id="CVE-2013-1848"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1979" ref_id="CVE-2013-1979"/>
        <description>[2.6.39-400.109.1] 

- while removing a non-empty directory, the kernel dumps a message: (rmdir,21743,1):ocfs2_unlink:953 ERROR: status = -39 (Xiaowei.Hu) [Orabug: 16790405] 

- stop mig handler when lockres in progress ,and return -EAGAIN (Xiaowei.Hu) [Orabug: 16876446]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:41.637-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:00.406-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.627-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:128611"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129047"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:128502"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129046"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129468"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129277"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129380"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129477"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129377"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:128565"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129442"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27542" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1000 -- rgmanager security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>rgmanager</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1000.html" ref_id="ELSA-2011-1000"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3389" ref_id="CVE-2010-3389"/>
        <description>[2.0.52-21]
- rgmanager: Fix bad passing of SFL_FAILURE up
  (fix_bad_passing_of_sfl_failure_up.patch)
  Resolves: rhbz#711521</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:32.184-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:59.998-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.427-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:16:17.779-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:16:17.779-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="rgmanager is earlier than 0:2.0.52-21.el5" test_ref="oval:org.mitre.oval:tst:133458"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27541" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0189 -- ipa-client security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ipa-client</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0189.html" ref_id="ELSA-2013-0189"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5484" ref_id="CVE-2012-5484"/>
        <description>[2.1.3-5.2]
- Add missing man page option --ca-cert-file. (#878217)

[2.1.3-5.1]
- Fix python syntax backport issue in CVE patch. (#878217)

[2.1.3-5]
- Use secure method to retrieve IPA CA during client enrollment.
  CVE-2012-5484 (#878217)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:55.386-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:59.775-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.321-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:03:00.168-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:03:00.168-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="ipa-client is earlier than 0:2.1.3-5.el5_9.2" test_ref="oval:org.mitre.oval:tst:129596"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27538" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0690 -- bind97 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0690.html" ref_id="ELSA-2013-0690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2266" ref_id="CVE-2013-2266"/>
        <description>[32:9.7.0-17.P2.1]
- fix CVE-2013-2266</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:56.243-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:59.420-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.075-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:35:04.025-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:35:04.025-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 0:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:129616"/>
          <criterion comment="bind97-chroot is earlier than 0:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:129811"/>
          <criterion comment="bind97-devel is earlier than 0:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:129612"/>
          <criterion comment="bind97-libs is earlier than 0:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:129535"/>
          <criterion comment="bind97-utils is earlier than 0:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:129874"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27537" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0176 -- java-1.6.0-openjdk security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0176.html" ref_id="ELSA-2011-0176"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3860" ref_id="CVE-2010-3860"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4351" ref_id="CVE-2010-4351"/>
        <description>[1:1.6.0.0-1.17.b17.0.1.el5]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.17.b17.el5]
- Updated to 1.7.7 tarball
- Resolves: bz668487
- Also resolves bz668488</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:05.807-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:59.146-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:11.861-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:57:05.786-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:57:05.786-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.17.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134743"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.17.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134673"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.17.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134596"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.17.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134351"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.17.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134691"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27536" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0982 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0982.html" ref_id="ELSA-2013-0982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1682" ref_id="CVE-2013-1682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1684" ref_id="CVE-2013-1684"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1685" ref_id="CVE-2013-1685"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1686" ref_id="CVE-2013-1686"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1687" ref_id="CVE-2013-1687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1690" ref_id="CVE-2013-1690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1692" ref_id="CVE-2013-1692"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1693" ref_id="CVE-2013-1693"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1694" ref_id="CVE-2013-1694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1697" ref_id="CVE-2013-1697"/>
        <description>[17.0.7-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.7-1]
- Update to 17.0.7 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:16.032-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:58.316-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:11.364-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:22:17.752-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:22:17.752-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129369"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128850"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27535" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-1174-1 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1174-1.html" ref_id="ELSA-2012-1174-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313" ref_id="CVE-2012-2313"/>
        <description>kernel [2.6.18-308.13.1.0.1.el5] - [kernel] Initialize the local uninitialized
          variable stats. [orabug 14051367] - [fs] JBD:make jbd support 512B blocks correctly for
          ocfs2. [orabug 13477763] - [x86 ] fix fpu context corrupt when preempt in signal context
          [orabug 14038272] - [net] bonding: fix carrier detect when bond is down [orabug 12377284]
          - [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075] - fix ia64 build error due
          to add-support-above-32-vcpus.patch(Zhenzhong Duan) - [x86] use dynamic vcpu_info remap to
          support more than 32 vcpus (Zhenzhong Duan) - [x86] Fix lvt0 reset when hvm boot up with
          noapic param - [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris
          Mason) [orabug 12342275] - [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin)
          [orabug 12561346] - [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
          - [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
          - [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646] -
          [scsi] fix scsi hotplug and rescan race [orabug 10260172] - fix filp_close() race (Joe
          Jin) [orabug 10335998] - make xenkbd.abs_pointer=1 by default [orabug 67188919] - [xen]
          check to see if hypervisor supports memory reservation change (Chuck Anderson) [orabug
          7556514] - [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John
          Sobecki) [orabug 10315433] - [NET] Add xen pv netconsole support (Tina Yang) [orabug
          6993043] [bz 7258] - [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839] -
          fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042] - [rds] Patch rds to
          1.4.2-20 (Andy Grover) [orabug 9471572, 9344105] RDS: Fix BUG_ONs to not fire when in a
          tasklet ipoib: Fix lockup of the tx queue RDS: Do not call set_page_dirty() with irqs off
          (Sherman Pun) RDS: Properly unmap when getting a remote access error (Tina Yang) RDS: Fix
          locking in rds_send_drop_to() - [xen] PVHVM guest with PoD crashes under memory pressure
          (Chuck Anderson) [orabug 9107465] - [xen] PV guest with FC HBA hangs during shutdown
          (Chuck Anderson) [orabug 9764220] - Support 256GB+ memory for pv guest (Mukesh Rathor)
          [orabug 9450615] - fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
          Guru Anbalagane) [orabug 6124033] - [ipmi] make configurable timeouts for kcs of ipmi
          [orabug 9752208] - [ib] fix memory corruption (Andy Grover) [orabug 9972346]
          [2.6.18-308.13.1.el5] - [net] e1000e: Cleanup logic in e1000_check_for_serdes_link_82571
          (Dean Nelson) [841370 771366] - [net] e1000e: Correct link check logic for 82571 serdes
          (Dean Nelson) [841370 771366] - [mm] NULL pointer dereference in __vm_enough_memory
          (Jerome Marchand) [840077 836244] - [fs] dlm: fix slow rsb search in dir recovery (David
          Teigland) [838140 753244] - [fs] autofs: propogate LOOKUP_DIRECTORY flag only for last
          comp (Ian Kent) [830264 814418] - [fs] ext4: properly dirty split extent nodes (Eric
          Sandeen) [840946 839770] - [scsi] don't offline devices with a reservation conflict (David
          Jeffery) [839196 835660] - [fs] ext4: Fix overflow caused by missing cast in
          ext4_fallocate (Lukas Czerner) [837226 830351] - [net] dl2k: Clean up rio_ioctl (Weiping
          Pan) [818822 818823] {CVE-2012-2313} - [x86] sched: Avoid unnecessary overflow in
          sched_clock (Prarit Bhargava) [835450 834562] - [net] tg3: Fix TSO handling (John Feeney)
          [833182 795672] - [input] evdev: use after free from open/disconnect race (David Jeffery)
          [832448 822166] [2.6.18-308.12.1.el5] - [fs] nfs: Don't allow multiple mounts on same
          mntpnt with -o noac (Sachin Prabhu) [839806 839753]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:17.076-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:58.072-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:11.232-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27535 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:35.797-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:23.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131065"/>
          <criterion comment="ocfs2-2.6.18-308.13.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130954"/>
          <criterion comment="oracleasm-2.6.18-308.13.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131249"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131082"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131022"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131346"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131196"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131121"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131307"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131286"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130376"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.13.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130772"/>
          <criterion comment="ocfs2-2.6.18-308.13.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131049"/>
          <criterion comment="ocfs2-2.6.18-308.13.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130895"/>
          <criterion comment="ocfs2-2.6.18-308.13.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131042"/>
          <criterion comment="oracleasm-2.6.18-308.13.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131318"/>
          <criterion comment="oracleasm-2.6.18-308.13.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131285"/>
          <criterion comment="oracleasm-2.6.18-308.13.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130675"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27534" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1149 -- sudo security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1149.html" ref_id="ELSA-2012-1149"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3440" ref_id="CVE-2012-3440"/>
        <description>[1.7.2p1-14.2]
- added a workaround for a race condition in handling child processes 
  Resolves: rhbz#844978

[1.7.2p1-14.1]
- dont remove the sudoers: line from nsswitch.conf on update
- use safe temporary file for nsswitch.conf
- call restorecon after modifying nsswitch.conf
- fixed command escaping
- patch: Use SIG_SETMASK when resetting signal mask instead of SIG_UNBLOCK
  Resolves: rhbz#842759
  Resolves: rhbz#844420
  Resolves: rhbz#844419
  Resolves: rhbz#844418
  Resolves: rhbz#844443</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:31.893-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:57.897-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:11.109-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:56:30.338-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:56:30.338-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8.2" test_ref="oval:org.mitre.oval:tst:131186"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27533" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1050 -- php53 security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1050.html" ref_id="ELSA-2013-1050"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4113" ref_id="CVE-2013-4113"/>
        <description>[5.3.3-13.1]
- add security fix for CVE-2013-4113</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:30.708-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:57.698-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:10.949-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:52:58.906-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:52:58.906-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php53 is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129308"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129048"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128674"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129211"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129206"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129145"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128742"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128465"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128887"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128954"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129267"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129299"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129301"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128839"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128431"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129199"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128662"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129229"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:128781"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129286"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:129372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27532" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0271 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
          <product>libproxy</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0271.html" ref_id="ELSA-2013-0271"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0780" ref_id="CVE-2013-0780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0783" ref_id="CVE-2013-0783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0776" ref_id="CVE-2013-0776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0782" ref_id="CVE-2013-0782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0775" ref_id="CVE-2013-0775"/>
        <description>firefox
[17.0.3-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.3-1]
- Update to 17.0.3 ESR

[17.0.2-4]
- Added NM preferences

[17.0.2-3]
- Update to 17.0.2 ESR
libproxy
[0.3.0-4]
- Rebuild against newer gecko

xulrunner
[17.0.3-1.0.2]
- Increase release number and rebuild.

[17.0.3-1.0.1]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.3-1]
- Update to 17.0.3 ESR

[17.0.2-5]
- Fixed NetworkManager preferences
- Added fix for NM regression (mozbz#791626)

[17.0.2-2]
- Added fix for rhbz#816234 - NFS fix

[17.0.2-1]
- Update to 17.0.2 ESR

[17.0.1-3]
- Update to 17.0.1 ESR

[17.0-1]
- Update to 17.0 ESR

[17.0-0.6.b5]
- Update to 17 Beta 5
- Updated fix for rhbz#872752 - embeded crash

[17.0-0.5.b4]
- Added fix for rhbz#872752 - embeded crash

[17.0-0.4.b4]
- Update to 17 Beta 4

[17.0-0.3.b3]
- Update to 17 Beta 3
- Updated ppc(64) patch (mozbz#746112)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:52.480-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:57.166-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:10.672-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:30:32.842-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:30:32.842-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="devhelp is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:130366"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130358"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130072"/>
            <criterion comment="yelp is earlier than 0:2.16.0-30.el5_9" test_ref="oval:org.mitre.oval:tst:130124"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:129973"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130278"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.3-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130418"/>
            <criterion comment="libproxy is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:129699"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:129966"/>
            <criterion comment="yelp is earlier than 0:2.28.1-17.el6_3" test_ref="oval:org.mitre.oval:tst:130181"/>
            <criterion comment="libproxy-bin is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130209"/>
            <criterion comment="libproxy-devel is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130273"/>
            <criterion comment="libproxy-gnome is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130114"/>
            <criterion comment="libproxy-kde is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130443"/>
            <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130359"/>
            <criterion comment="libproxy-python is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:129879"/>
            <criterion comment="libproxy-webkit is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130407"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130125"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27521" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0465 -- samba security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0465.html" ref_id="ELSA-2012-0465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182" ref_id="CVE-2012-1182"/>
        <description>[3.5.10-115]
- Security Release, fixes CVE-2012-1182
- resolves: #804644</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:26.274-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:55.749-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:09.429-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:49:33.844-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:49:33.844-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132187"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132253"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132541"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132589"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132438"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132367"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132586"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132483"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:131886"/>
            <criterion comment="samba-client is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132416"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132479"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132574"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132525"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132223"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132373"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132555"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132153"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132264"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27518" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2019 -- Oracle Linux 6 Unbreakable Enterprise kernel security fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2019.html" ref_id="ELSA-2011-2019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598" ref_id="CVE-2011-1598"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1748" ref_id="CVE-2011-1748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770" ref_id="CVE-2011-1770"/>
        <description>[2.6.32-100.35.1.el6uek] - [net] dccp: handle invalid feature options length
          {CVE-2011-1770} - [net] can: add missing socket check in can/raw release {CVE-2011-1748} -
          [net] can: Add missing socket check in can/bcm release {CVE-2011-1598}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:29.360-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:54.847-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:08.815-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36931 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:39.680-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:22.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133600"/>
            <criterion comment="ofa-2.6.32-100.35.1.el5uek is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133341"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:132853"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133705"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133681"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133352"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133775"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133644"/>
            <criterion comment="ofa-2.6.32-100.35.1.el5uekdebug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133664"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133714"/>
            <criterion comment="ofa-2.6.32-100.35.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133739"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133789"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133268"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133785"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:132920"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133647"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133657"/>
            <criterion comment="ofa-2.6.32-100.35.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132851"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27517" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2503 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2503.html" ref_id="ELSA-2013-2503"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4398" ref_id="CVE-2012-4398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4461" ref_id="CVE-2012-4461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4530" ref_id="CVE-2012-4530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0190" ref_id="CVE-2013-0190"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0231" ref_id="CVE-2013-0231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0216" ref_id="CVE-2013-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0217" ref_id="CVE-2013-0217"/>
        <description>[2.6.39-300.28.1]

- kmod: make __request_module() killable (Oleg Nesterov) [Orabug: 16286305]

  {CVE-2012-4398}

- kmod: introduce call_modprobe() helper (Oleg Nesterov) [Orabug: 16286305]

  {CVE-2012-4398}

- usermodehelper: implement UMH_KILLABLE (Oleg Nesterov) [Orabug: 16286305]

  {CVE-2012-4398}

- usermodehelper: introduce umh_complete(sub_info) (Oleg Nesterov) [Orabug:

  16286305] {CVE-2012-4398}

- KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set

  (CVE-2012-4461) (Jerry Snitselaar) [Orabug: 16286290] {CVE-2012-4461}

- exec: do not leave bprm->interp on stack (Kees Cook) [Orabug: 16286267]

  {CVE-2012-4530}

- exec: use -ELOOP for max recursion depth (Kees Cook) [Orabug: 16286267]

  {CVE-2012-4530}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:55.820-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:54.252-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:08.590-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:129523"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:130274"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:130338"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:130392"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:129940"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:129839"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130506"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130306"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130325"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130042"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:129926"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27516" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0306 -- samba3x security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0306.html" ref_id="ELSA-2011-0306"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0719" ref_id="CVE-2011-0719"/>
        <description>[3.5.4-0.70.1]
- Security Release, fixes CVE-2011-0719
- resolves: #678332</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:08.747-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:54.054-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:08.474-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:19:15.986-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:19:15.986-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba3x is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:133253"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:134204"/>
          <criterion comment="samba3x-common is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:134254"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:133977"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:133811"/>
          <criterion comment="samba3x-swat is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:133893"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:134136"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:134161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27513" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1135 -- nss and nspr security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1135.html" ref_id="ELSA-2013-1135"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0791" ref_id="CVE-2013-0791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1620" ref_id="CVE-2013-1620"/>
        <description>nspr
[4.9.2-4]
- Resolves: rhbz#924741 - Rebase to nspr-4.9.5

nss
[3.14.3-6]
- Resolves: rhbz#986969 - nssutil_ReadSecmodDB() leaks memory

[3.14.3-5]
- Define -DNO_FORK_CHECK when compiling softoken for ABI compatibility
- Remove the unused and obsolete nss-nochktest.patch
- Resolves: rhbz#949845 - [RFE][RHEL5] Rebase to nss-3.14.3 to fix the lucky-13 issue

[3.14.3-4]
- Fix rpmdiff test reported failures and remove other unwanted changes
- Resolves: rhbz#949845 - [RFE][RHEL5] Rebase to nss-3.14.3 to fix the lucky-13 issue

[3.14.3-3]
- Update to NSS_3_14_3_RTM
- Rework the rebase to preserve needed idiosynchracies
- Ensure we install frebl/softoken from the extra build tree
- Don't include freebl static library or its private headers
- Add patch to deal with system sqlite not being recent enough
- Don't install nss-sysinit nor sharedb
- Resolves: rhbz#949845 - [RFE][RHEL5] Rebase to nss-3.14.3 to fix the lucky-13 issue

[3.14.3-2]
- Restore the freebl-softoken source tar ball updated to 3.14.3
- Renumbering of some sources for clarity
- Resolves: rhbz#918870 - [RFE][RHEL5] Rebase to nss-3.14.3 to fix the lucky-13 issue

[3.14.3-1]
- Update to NSS_3_14_3_RTM
- Resolves: rhbz#918870 - [RFE][RHEL5] Rebase to nss-3.14.3 to fix the lucky-13 issue</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:25.220-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:53.572-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:08.177-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:43:13.606-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:43:13.606-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.9.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:128926"/>
          <criterion comment="nss is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:128790"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:129053"/>
          <criterion comment="nss-devel is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:129102"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:129085"/>
          <criterion comment="nss-tools is earlier than 0:3.14.3-6.el5_9" test_ref="oval:org.mitre.oval:tst:129260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27512" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-0304 -- vixie-cron security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>vixie-cron</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0304.html" ref_id="ELSA-2012-0304"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0424" ref_id="CVE-2010-0424"/>
        <description>[4:4.1-81]
- 455664 adoptions of crontab orphans, forgot add buffer for list of
  orphans
- Related: rhbz#455664</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:06.909-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:53.414-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:07.906-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="vixie-cron is earlier than 0:4.1-81.el5" test_ref="oval:org.mitre.oval:tst:132421"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27510" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1359 -- xorg-x11-server security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1359.html" ref_id="ELSA-2011-1359"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4818" ref_id="CVE-2010-4818"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4819" ref_id="CVE-2010-4819"/>
        <description>[1.7.7-29.2]
- cve-2011-4818.patch: Multiple input sanitization flaws in GLX and Render</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:11.253-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:53.098-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:07.668-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:46:38.464-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:46:38.464-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133055"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133388"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133256"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133439"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133305"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132930"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133426"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133378"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133203"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133381"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133120"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133020"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133035"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:132723"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133409"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133384"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133375"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27509" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0246 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0246.html" ref_id="ELSA-2013-0246"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0424" ref_id="CVE-2013-0424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0425" ref_id="CVE-2013-0425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0426" ref_id="CVE-2013-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0427" ref_id="CVE-2013-0427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0428" ref_id="CVE-2013-0428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0429" ref_id="CVE-2013-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0432" ref_id="CVE-2013-0432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0433" ref_id="CVE-2013-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0434" ref_id="CVE-2013-0434"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0435" ref_id="CVE-2013-0435"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0440" ref_id="CVE-2013-0440"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0441" ref_id="CVE-2013-0441"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0442" ref_id="CVE-2013-0442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0443" ref_id="CVE-2013-0443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0445" ref_id="CVE-2013-0445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0450" ref_id="CVE-2013-0450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1475" ref_id="CVE-2013-1475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1476" ref_id="CVE-2013-1476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1478" ref_id="CVE-2013-1478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1480" ref_id="CVE-2013-1480"/>
        <description>[ 1:1.6.0.0-1.33.1.11.6.0.1.el5_9]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.33.1.11.6]
- removed patch9 revertTwoWrongSecurityPatches2013-02-06.patch
- added patch9:   7201064.patch to be reverted
- added patch10:   8005615.patch to fix the 6664509.patch
- Resolves: rhbz#906705

[1:1.6.0.0-1.32.1.11.6]
- added patch9 revertTwoWrongSecurityPatches2013-02-06.patch
  to remove   6664509 and 7201064 from 1.11.6 tarball
- Resolves: rhbz#906705

[1:1.6.0.0-1.31.1.11.6]
- Updated to icedtea6 1.11.6
- Rewritten java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#906705</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:42.723-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:52.946-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:07.482-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:21:44.928-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:21:44.928-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.33.1.11.6.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129496"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.33.1.11.6.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130339"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.33.1.11.6.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129771"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.33.1.11.6.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129828"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.33.1.11.6.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27504" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0668 -- boost security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>boost</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0668.html" ref_id="ELSA-2013-0668"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2677" ref_id="CVE-2012-2677"/>
        <description>[1.41.0-15]
- Add in explicit dependences between some boost subpackages

[1.41.0-14]
- Build with -fno-strict-aliasing

[1.41.0-13]
- In Boost.Pool, be careful not to overflow allocated chunk size
  (boost-1.41.0-pool.patch)

[1.41.0-12]
- Add an upstream patch that fixes computation of CRC in zlib streams.
- Resolves: #707624</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:34.941-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:52.029-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:06.665-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:02:23.302-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:02:23.302-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="boost is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:129813"/>
            <criterion comment="boost-devel is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:129814"/>
            <criterion comment="boost-doc is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:129094"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="boost is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129521"/>
            <criterion comment="boost-date-time is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129872"/>
            <criterion comment="boost-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129918"/>
            <criterion comment="boost-doc is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129575"/>
            <criterion comment="boost-filesystem is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129689"/>
            <criterion comment="boost-graph is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129919"/>
            <criterion comment="boost-graph-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129730"/>
            <criterion comment="boost-graph-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129623"/>
            <criterion comment="boost-iostreams is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129830"/>
            <criterion comment="boost-math is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129900"/>
            <criterion comment="boost-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129888"/>
            <criterion comment="boost-mpich2-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129182"/>
            <criterion comment="boost-mpich2-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129227"/>
            <criterion comment="boost-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129064"/>
            <criterion comment="boost-openmpi-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129837"/>
            <criterion comment="boost-openmpi-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129607"/>
            <criterion comment="boost-program-options is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129766"/>
            <criterion comment="boost-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129917"/>
            <criterion comment="boost-regex is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129642"/>
            <criterion comment="boost-serialization is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129908"/>
            <criterion comment="boost-signals is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129577"/>
            <criterion comment="boost-static is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129806"/>
            <criterion comment="boost-system is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129778"/>
            <criterion comment="boost-test is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129875"/>
            <criterion comment="boost-thread is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129309"/>
            <criterion comment="boost-wave is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27499" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1323 -- ccid security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ccid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1323.html" ref_id="ELSA-2013-1323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4530" ref_id="CVE-2010-4530"/>
        <description>[1.3.8-2]

- fix voltage issue</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:00.923-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:51.044-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:05.697-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="ccid is earlier than 0:1.3.8-2.el5" test_ref="oval:org.mitre.oval:tst:128897"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27498" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0533 -- pcsc-lite security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pcsc-lite</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0533.html" ref_id="ELSA-2010-0533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4901" ref_id="CVE-2009-4901"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0407" ref_id="CVE-2010-0407"/>
        <description>[1.4.4-4]
- Fix second typo in overflow patch from upstream

[1.4.4-3]
- Fix typo in patch

[1.4.4-2]
- Fix buffer overflow issues</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:12.385-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:50.771-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:05.502-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:34:09.512-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:34:09.512-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pcsc-lite is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:135072"/>
          <criterion comment="pcsc-lite-devel is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:134418"/>
          <criterion comment="pcsc-lite-doc is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:134953"/>
          <criterion comment="pcsc-lite-libs is earlier than 0:1.4.4-4.el5_5" test_ref="oval:org.mitre.oval:tst:135024"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27496" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0132 -- autofs security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>autofs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0132.html" ref_id="ELSA-2013-0132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2697" ref_id="CVE-2012-2697"/>
        <description>[5.0.1-0.rc2.177.0.1.el5]

- apply fix from NetApp to use tcp before udp

  http://www.mail-archive.com/autofs@linux.kernel.org/msg07910.html

  (Bert Barbe) [orabug 6827898]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:44.814-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:49.841-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:05.001-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:18:59.783-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:18:59.783-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="autofs is earlier than 0:5.0.1-0.rc2.177.0.1.el5" test_ref="oval:org.mitre.oval:tst:130635"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27495" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1034 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1034.html" ref_id="ELSA-2013-1034"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" ref_id="CVE-2013-1929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" ref_id="CVE-2012-6544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" ref_id="CVE-2012-6545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" ref_id="CVE-2013-0914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" ref_id="CVE-2013-3222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" ref_id="CVE-2013-3224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" ref_id="CVE-2013-3231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3235" ref_id="CVE-2013-3235"/>
        <description>kernel
[2.6.18-348.12.1]
- Revert: [fs] afs: export a couple of core functions for AFS write support (Lukas Czerner) [960014 692071]
- Revert: [fs] ext4: drop ec_type from the ext4_ext_cache structure (Lukas Czerner) [960014 692071]
- Revert: [fs] ext4: handle NULL p_ext in ext4_ext_next_allocated_block() (Lukas Czerner) [960014 692071]
- Revert: [fs] ext4: make FIEMAP and delayed allocation play well together (Lukas Czerner) [960014 692071]
- Revert: [fs] ext4: Fix possibly very long loop in fiemap (Lukas Czerner) [960014 692071]
- Revert: [fs] ext4: prevent race while walking extent tree for fiemap (Lukas Czerner) [960014 692071]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:26.286-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:49.616-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:04.821-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:52:38.064-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:52:38.064-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129368"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.12.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129348"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.12.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129410"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:128647"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129336"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129359"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129273"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129127"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129425"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129265"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:129400"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.12.1.el5" test_ref="oval:org.mitre.oval:tst:128918"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.12.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129337"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.12.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129209"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.12.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129169"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.12.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128438"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.12.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129281"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.12.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129297"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27494" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2524 -- Unbreakable Enterprise kernel Security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2524.html" ref_id="ELSA-2013-2524"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2094" ref_id="CVE-2013-2094"/>
        <description>[2.6.39-400.24.1]
- perf: Treat attr.config as u64 in perf_swevent_init() (Tommi Rantala) [Orabug: 16808734] {CVE-2013-2094}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:03.896-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:49.409-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:04.651-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129572"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129489"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129339"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:128633"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129569"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129495"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129389"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129554"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129266"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129610"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129471"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129478"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27493" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0610 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0610.html" ref_id="ELSA-2010-0610"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1084" ref_id="CVE-2010-1084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2066" ref_id="CVE-2010-2066"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2070" ref_id="CVE-2010-2070"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2226" ref_id="CVE-2010-2226"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2248" ref_id="CVE-2010-2248"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2521" ref_id="CVE-2010-2521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2524" ref_id="CVE-2010-2524"/>
        <description>[2.6.18-194.11.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb (John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN [orabug 7689332]
- [NET] Add xen pv/bonding netconsole support (Tina Yang) [orabug 6993043]
  [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- [qla] fix qla not to query hccr (Guru Anbalagane) [Orabug 8746702]
- [net] bonding: fix xen+bonding+netconsole panic issue (Joe Jin) [orabug 9504524]
- [rds] Patch rds to 1.4.2-14 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki, Chris Mason, Herbert van den Bergh)
  [orabug 9245919]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson) 
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson) 
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro, 
  Guru Anbalagane) [orabug 6124033]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:51.867-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:48.532-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:04.303-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:22:56.665-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:22:56.665-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135015"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.1.0.1.el5-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134515"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135007"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134758"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134816"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134957"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134272"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134770"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134375"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134650"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134493"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134504"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.1.0.1.el5PAE-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:135046"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.1.0.1.el5debug-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134952"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-194.11.1.0.1.el5xen-1.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:134902"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134899"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134879"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-194.11.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134900"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27491" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-1292-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1292-1.html" ref_id="ELSA-2013-1292-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3511" ref_id="CVE-2012-3511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2141" ref_id="CVE-2013-2141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4162" ref_id="CVE-2013-4162"/>
        <description>This update fixes the following security issues:

* A use-after-free flaw was found in the madvise() system call
implementation in the Linux kernel. A local, unprivileged user could use
this flaw to cause a denial of service or, potentially, escalate their
privileges. (CVE-2012-3511, Moderate)

* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled IPv6 sockets that used the UDP_CORK option. A local,
unprivileged user could use this flaw to cause a denial of service.
(CVE-2013-4162, Moderate)

* An information leak flaw in the Linux kernel could allow a local,
unprivileged user to leak kernel memory to user-space.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:59.884-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:47.675-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:03.808-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128797 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:56.451-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:21.387-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128758"/>
          <criterion comment="ocfs2-2.6.18-348.18.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128881"/>
          <criterion comment="oracleasm-2.6.18-348.18.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128805"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128913"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128857"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128980"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128541"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128746"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128853"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128855"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128461"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.18.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128779"/>
          <criterion comment="ocfs2-2.6.18-348.18.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128819"/>
          <criterion comment="ocfs2-2.6.18-348.18.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128999"/>
          <criterion comment="ocfs2-2.6.18-348.18.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129051"/>
          <criterion comment="oracleasm-2.6.18-348.18.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128797"/>
          <criterion comment="oracleasm-2.6.18-348.18.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128505"/>
          <criterion comment="oracleasm-2.6.18-348.18.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129041"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27490" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0214 -- nss and nspr security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nspr-devel</product>
          <product>nss-devel</product>
          <product>nss-pkcs11-devel</product>
          <product>nss-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0214.html" ref_id="ELSA-2013-0214"/>
        <description>nspr
[4.9.2-2]
- NVR bump

[4.9.2-1]
- Resolves: rhbz#893372- [RFE] Rebase nspr to 4.9.2 due to Firefox 17 ESR

nss
[3.13.6-3]
- Fix changelog inconsistencies with commit and bug resolved
- Resolves: rhbz#891149 [CVE-2013-0743]

[3.13.6-2]
- [CVE-2013-0743] - Resolves: rhbz#891149 - Dis-trust TURKTRUST mis-issued *.google.com certificate

[3.13.6-1]
- Update to NSS_3_13_6_RTM
- Resolves: rhbz#893371 - [RFE] [RHEL5] Rebase to NSS >= 3.13.6</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:53.491-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:47.557-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:03.663-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:39:03.800-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:39:03.800-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.9.2-2.el5_9" test_ref="oval:org.mitre.oval:tst:130566"/>
          <criterion comment="nss is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:130458"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.2-2.el5_9" test_ref="oval:org.mitre.oval:tst:130492"/>
          <criterion comment="nss-devel is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:129739"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:129581"/>
          <criterion comment="nss-tools is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:129582"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27487" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0611 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0611.html" ref_id="ELSA-2013-0611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1821" ref_id="CVE-2013-1821"/>
        <description>[1.8.5-29]
- Fix regression introduced by fix for entity expansion DOS vulnerability
  in REXML (https://bugs.ruby-lang.org/issues/7961)
  * ruby-2.0.0-add-missing-rexml-require.patch
- Related: rhbz#915377

[1.8.5-28]
- Addresses entity expansion DoS vulnerability in REXML.
  * ruby-2.0.0-entity-expansion-DoS-vulnerability-in-REXML.patch
- Resolves: rhbz#915377</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:36.652-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:46.952-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:03.281-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:35:39.929-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:35:39.929-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:129731"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:130101"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:129452"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:130120"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:130089"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:130084"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:130059"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:130070"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:129626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27484" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1480 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1480.html" ref_id="ELSA-2013-1480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5590" ref_id="CVE-2013-5590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5595" ref_id="CVE-2013-5595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5597" ref_id="CVE-2013-5597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5599" ref_id="CVE-2013-5599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5600" ref_id="CVE-2013-5600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5601" ref_id="CVE-2013-5601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5602" ref_id="CVE-2013-5602"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5604" ref_id="CVE-2013-5604"/>
        <description>[17.0.10-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.10-1]
- Update to 17.0.10 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:53.140-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:43.553-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.817-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:09:08.563-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:09:08.563-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128697"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27481" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0821 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0821.html" ref_id="ELSA-2013-0821"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0801" ref_id="CVE-2013-0801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1670" ref_id="CVE-2013-1670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1674" ref_id="CVE-2013-1674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1675" ref_id="CVE-2013-1675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1676" ref_id="CVE-2013-1676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1677" ref_id="CVE-2013-1677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1678" ref_id="CVE-2013-1678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1679" ref_id="CVE-2013-1679"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1680" ref_id="CVE-2013-1680"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1681" ref_id="CVE-2013-1681"/>
        <description>[17.0.6-2.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.6-2]
- Update to 17.0.6 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:48.336-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:41.964-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.199-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:12:52.259-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:12:52.259-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129576"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129457"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27479" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1047 -- php53 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1047.html" ref_id="ELSA-2012-1047"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2143" ref_id="CVE-2012-2143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4153" ref_id="CVE-2011-4153"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0057" ref_id="CVE-2012-0057"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0789" ref_id="CVE-2012-0789"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1172" ref_id="CVE-2012-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2336" ref_id="CVE-2012-2336"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2950" ref_id="CVE-2010-2950"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2386" ref_id="CVE-2012-2386"/>
        <description>[5.3.3-13]
- add security fix for CVE-2010-2950

[5.3.3-11]
- fix tests for CVE-2012-2143, CVE-2012-0789

[5.3.3-10]
- add security fix for CVE-2012-2336

[5.3.3-9]
- add security fixes for CVE-2011-4153, CVE-2012-0057, CVE-2012-0789,
  CVE-2012-1172, CVE-2012-2143, CVE-2012-2386</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:35.729-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:40.975-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:01.757-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:46:16.868-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:46:16.868-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php53 is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131728"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131766"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:130866"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131107"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131570"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131480"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131736"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131747"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131537"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131309"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131635"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131659"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131803"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131555"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131713"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131389"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131698"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131761"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131596"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131816"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:131665"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27478" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0752 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0752.html" ref_id="ELSA-2013-0752"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0401" ref_id="CVE-2013-0401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1488" ref_id="CVE-2013-1488"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1558" ref_id="CVE-2013-1558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2417" ref_id="CVE-2013-2417"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2419" ref_id="CVE-2013-2419"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2436" ref_id="CVE-2013-2436"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2420" ref_id="CVE-2013-2420"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2422" ref_id="CVE-2013-2422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1557" ref_id="CVE-2013-1557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2384" ref_id="CVE-2013-2384"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2429" ref_id="CVE-2013-2429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1569" ref_id="CVE-2013-1569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2430" ref_id="CVE-2013-2430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1537" ref_id="CVE-2013-1537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1518" ref_id="CVE-2013-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2415" ref_id="CVE-2013-2415"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2426" ref_id="CVE-2013-2426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2423" ref_id="CVE-2013-2423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2424" ref_id="CVE-2013-2424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2431" ref_id="CVE-2013-2431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2383" ref_id="CVE-2013-2383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2421" ref_id="CVE-2013-2421"/>
        <description>[1.7.0.19-2.3.9.1.0.1.el5_9]

- Add oracle-enterprise.patch

- Fix DISTRO_NAME to "Enterprise Linux"</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:45.194-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:40.686-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:01.556-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:03:43.295-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:03:43.295-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.19-2.3.9.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129758"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.19-2.3.9.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129761"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.19-2.3.9.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129703"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.19-2.3.9.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128967"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.19-2.3.9.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129591"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27476" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1353 -- sudo security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1353.html" ref_id="ELSA-2013-1353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1775" ref_id="CVE-2013-1775"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1776" ref_id="CVE-2013-1776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2776" ref_id="CVE-2013-2776"/>
        <description>[1.7.2p1-28]

- backported fixes for CVE-2013-1775 CVE-2013-1776 CVE-2013-2776 CVE-2013-2777

  Resolves: rhbz#968221</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:21.135-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:40.527-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:01.449-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-28.el5" test_ref="oval:org.mitre.oval:tst:128985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27475" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0676 -- kvm security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0676.html" ref_id="ELSA-2012-0676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1601" ref_id="CVE-2012-1601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2121" ref_id="CVE-2012-2121"/>
        <description>[kvm-83-249.0.1.el5_8.4]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch

[kvm-83-249.el5_8.4]
- kvm-kernel-KVM-unmap-pages-from-the-iommu-when-slots-are-remove.patch [bz#814151]
- CVE: CVE-2012-2121
- Resolves: bz#814151
  (CVE-2012-2121 kvm: device assignment page leak [rhel-5.8])

[kvm-83-249.el5_8.3]
- kvm-fix-l1_map-buffer-overflow.patch [bz#816207]
- Resolves: bz#816207
  (qemu-kvm segfault in tb_invalidate_phys_page_range())

[kvm-83-249.el5_8.2]
- kvm-kernel-KVM-Ensure-all-vcpus-are-consistent-with-in-kernel-i.patch [bz#808205]
- Resolves: bz#808205
  (CVE-2012-1601 kernel: kvm: irqchip_in_kernel() and vcpu->arch.apic inconsistency [rhel-5.8.z])

[kvm-83-249.el5_8.1]
- kvm-posix-aio-compat-fix-thread-accounting-leak.patch [bz#802429]
- Resolves: bz#802429
  ([RHEL5.8 Snapshot2]RHEL5.8 KVMGuest hung during Guest OS booting up)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:03.008-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:40.273-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:01.331-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:55:28.519-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:55:28.519-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-249.0.1.el5_8.4" test_ref="oval:org.mitre.oval:tst:132088"/>
          <criterion comment="kmod-kvm is earlier than 0:83-249.0.1.el5_8.4" test_ref="oval:org.mitre.oval:tst:132225"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-249.0.1.el5_8.4" test_ref="oval:org.mitre.oval:tst:132172"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-249.0.1.el5_8.4" test_ref="oval:org.mitre.oval:tst:132042"/>
          <criterion comment="kvm-tools is earlier than 0:83-249.0.1.el5_8.4" test_ref="oval:org.mitre.oval:tst:132030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27474" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0309 -- sudo security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0309.html" ref_id="ELSA-2012-0309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0010" ref_id="CVE-2011-0010"/>
        <description>[1.7.2p1-13]
- patch: parse ldap.conf more closely to nss_ldap
  Resolves: rhbz#750318

[1.7.2p1-12]
- added patch for CVE-2011-0010
  Resolves: rhbz#757157

[1.7.2p1-11]
- backported selinux support from 1.7.4p5 (#477185, #673157)
- fixed bug in Runas_Spec group matching (#627543)
- disable 'sudo -l' output word wrapping if the output
  is piped (#697111)
- fixed overwriting of errno after execve failure (#673157)
- fixed segmentation fault (#673072)
- add a sudoers entry to the nsswitch.conf file
  on install (and delete it on uninstall) (#617061)
  Resolves: rhbz#697111
  Resolves: rhbz#673157
  Resolves: rhbz#673072
  Resolves: rhbz#627543
  Resolves: rhbz#617061
  Resolves: rhbz#477185</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:30.393-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:40.092-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:01.197-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:50:14.166-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:50:14.166-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-13.el5" test_ref="oval:org.mitre.oval:tst:132701"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27473" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0870 -- tomcat5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0870.html" ref_id="ELSA-2013-0870"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1976" ref_id="CVE-2013-1976"/>
        <description>[0:5.5.23-0jpp.40]
- Related: CVE-2013-1976 It was found during additional testing
- that the tomcat5 init may fail to start because the user
- shell is set to sbin/nologin. Fixed in init scrip. SU now
- uses -s /bin/sh during startup

[0:5.5.23-0jpp.39]
- Resolves: CVE-2013-1976 Improper TOMCAT_LOG management in
- initscript. Change location of TOMCAT_LOG to /var/log so
- only root can write to it. Touching TOMCAT_LOG is no longer
- required during initscript startup. Permissions and ownership
- changed to 0755 tomcat:root for logdir</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:36.253-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:39.902-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:01.011-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:34:46.978-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:34:46.978-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129542"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129362"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129354"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129525"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129497"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129530"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129436"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:128711"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:128931"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129456"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:129480"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27472" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1426 -- xorg-x11-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1426.html" ref_id="ELSA-2013-1426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4396" ref_id="CVE-2013-4396"/>
        <description>[1.13.0-11.1.2]
- CVE-2013-4396: Fix use-after free in ImageText requests (#1014561)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:15.245-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:39.673-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:00.756-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:08:35.517-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:08:35.517-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128704"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128788"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128866"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128337"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128608"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:129015"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128868"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128612"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:129021"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128304"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128714"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128951"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128769"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:129004"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128901"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128749"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128922"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27471" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0216 -- freetype security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0216.html" ref_id="ELSA-2013-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5669" ref_id="CVE-2012-5669"/>
        <description>[2.3.11-14.el6_3.1]
- Fix CVE-2012-5669
    (Use correct array size for checking 'glyph_enc')
- Resolves: #903542

[2.3.11-14]
- A little change in configure part
- Related: #723468</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:30.380-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:39.480-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:00.587-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:12:24.704-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:12:24.704-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:130534"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:130493"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:130516"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130160"/>
            <criterion comment="freetype-demos is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:129936"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130545"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27469" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1166 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1166.html" ref_id="ELSA-2013-1166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2147" ref_id="CVE-2013-2147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2164" ref_id="CVE-2013-2164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" ref_id="CVE-2013-2206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2224" ref_id="CVE-2013-2224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" ref_id="CVE-2013-2232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" ref_id="CVE-2013-2234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" ref_id="CVE-2013-2237"/>
        <description>kernel
[2.6.18-348.16.1]
- [x86_64] Fix kdump failure due to 'x86_64: Early segment setup' (Paolo Bonzini) [988251 987244]
- [xen] skip tracing if it was disabled instead of dying (Igor Mammedov) [987976 967053]
- [ia64] fix KABI breakage on ia64 (Prarit Bhargava) [966878 960783]
- [x86] fpu: fix CONFIG_PREEMPT=y corruption of FPU stack (Prarit Bhargava) [948187 731531]
- [i386] add sleazy FPU optimization (Prarit Bhargava) [948187 731531]
- [x86-64] non lazy 'sleazy' fpu implementation (Prarit Bhargava) [948187 731531]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:28.160-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:38.096-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:59.417-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:15:00.797-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:15:00.797-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:128737"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.16.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129130"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.16.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128290"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:128753"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:129208"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:128876"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:128740"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:129200"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:128638"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:128845"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:129268"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:128949"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.16.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129018"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.16.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129101"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.16.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129026"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.16.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129073"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.16.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129056"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.16.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128953"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27466" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2534 -- Unbreakable Enterprise kernel Security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2534.html" ref_id="ELSA-2013-2534"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4542" ref_id="CVE-2012-4542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" ref_id="CVE-2012-6542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1943" ref_id="CVE-2013-1943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" ref_id="CVE-2013-1929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1860" ref_id="CVE-2013-1860"/>
        <description>[2.6.32-400.29.1]
- KVM: add missing void __user COPYING CREDITS Documentation Kbuild MAINTAINERS Makefile README REPORTING-BUGS arch block crypto drivers firmware fs include init ipc kernel lib mm net samples scripts security sound tools uek-rpm usr virt cast to access_ok() call (Heiko Carstens) [Orabug: 16941620] {CVE-2013-1943}
- KVM: Validate userspace_addr of memslot when registered (Takuya Yoshikawa) [Orabug: 16941620] {CVE-2013-1943}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:37.079-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:37.245-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:58.614-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35850 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:00.661-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:20.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129179"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129445"/>
            <criterion comment="ofa-2.6.32-400.29.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129141"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129287"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:128631"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129107"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:128513"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129472"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129458"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129371"/>
            <criterion comment="ofa-2.6.32-400.29.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129500"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:128923"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129466"/>
            <criterion comment="ofa-2.6.32-400.29.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129122"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129207"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129379"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129192"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129488"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:128553"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129089"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128523"/>
            <criterion comment="ofa-2.6.32-400.29.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129113"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27465" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0133 -- hplip3 security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>hplip3</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0133.html" ref_id="ELSA-2013-0133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2722" ref_id="CVE-2011-2722"/>
        <description>[3.9.8-15]
- Another D-Bus fix, part of bug #501834.

[3.9.8-14]

- Create debugging files securely (CVE-2011-2722, bug #725830).

[3.9.8-13]

- Several parallel-install fixes (bug #501834).

[3.9.8-12]

- Applied patch to fix CVE-2010-4267, remote stack overflow

  vulnerability (bug #662740).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:26.126-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:37.073-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:58.449-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:04:41.905-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:04:41.905-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="hplip3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:129776"/>
          <criterion comment="hpijs3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:130669"/>
          <criterion comment="hplip3-common is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:130700"/>
          <criterion comment="hplip3-gui is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:129909"/>
          <criterion comment="hplip3-libs is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:130766"/>
          <criterion comment="libsane-hpaio3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:130554"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27462" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0523 -- libpng security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0523.html" ref_id="ELSA-2012-0523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3048" ref_id="CVE-2011-3048"/>
        <description>[2:1.2.49-1]
- Update to libpng 1.2.49, for minor security issues (CVE-2011-3048)
Resolves: #812714</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:25.518-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:35.302-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:57.209-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:21:11.244-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:21:11.244-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:131946"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:132291"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:132101"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:132191"/>
            <criterion comment="libpng-static is earlier than 0:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:132113"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27459" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1351 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1351.html" ref_id="ELSA-2012-1351"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1956" ref_id="CVE-2012-1956"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3982" ref_id="CVE-2012-3982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3986" ref_id="CVE-2012-3986"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3988" ref_id="CVE-2012-3988"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3990" ref_id="CVE-2012-3990"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3991" ref_id="CVE-2012-3991"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3992" ref_id="CVE-2012-3992"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3993" ref_id="CVE-2012-3993"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3994" ref_id="CVE-2012-3994"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3995" ref_id="CVE-2012-3995"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4179" ref_id="CVE-2012-4179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4180" ref_id="CVE-2012-4180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4181" ref_id="CVE-2012-4181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4182" ref_id="CVE-2012-4182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4183" ref_id="CVE-2012-4183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4184" ref_id="CVE-2012-4184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4185" ref_id="CVE-2012-4185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4186" ref_id="CVE-2012-4186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4187" ref_id="CVE-2012-4187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4188" ref_id="CVE-2012-4188"/>
        <description>[10.0.8-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.8-1]
- Update to 10.0.8 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:14.069-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:33.259-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:56.031-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:25:18.016-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:25:18.016-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.0.2.el5_8" test_ref="oval:org.mitre.oval:tst:130685"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131100"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27458" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0683 -- axis security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0683.html" ref_id="ELSA-2013-0683"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5784" ref_id="CVE-2012-5784"/>
        <description>[0:1.2.1-2jpp.7]
- Add missing connection hostname check against X.509 certificate name
- Resolves: CVE-2012-5784
- Add patches to build with java 1.6</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:50.641-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:33.085-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:55.881-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:00:06.877-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:00:06.877-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="axis is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:129855"/>
          <criterion comment="axis-javadoc is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:129841"/>
          <criterion comment="axis-manual is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:129316"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27454" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2519 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2519.html" ref_id="ELSA-2013-2519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1774" ref_id="CVE-2013-1774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1796" ref_id="CVE-2013-1796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1797" ref_id="CVE-2013-1797"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0349" ref_id="CVE-2013-0349"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1767" ref_id="CVE-2013-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1798" ref_id="CVE-2013-1798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1792" ref_id="CVE-2013-1792"/>
        <description>[2.6.39-400.21.2]
- KVM: x86: Convert MSR_KVM_SYSTEM_TIME to use gfn_to_hva_cache functions (CVE-2013-1797) (Andy Honig) [Orabug: 16711660] {CVE-2013-1797}
- Bluetooth: Fix incorrect strncpy() in hidp_setup_hid() (Anderson Lizardo) [Orabug: 16711065] {CVE-2013-0349}
- USB: io_ti: Fix NULL dereference in chase_port() (Wolfgang Frisch) [Orabug: 16425358] {CVE-2013-1774}
- keys: fix race with concurrent install_user_keyrings() (David Howells) [Orabug: 16493354] {CVE-2013-1792}
- KVM: Fix bounds checking in ioapic indirect register reads (CVE-2013-1798) (Andy Honig) [Orabug: 16710951] {CVE-2013-1798}
- KVM: x86: fix for buffer overflow in handling of MSR_KVM_SYSTEM_TIME (CVE-2013-1796) (Andy Honig) [Orabug: 16710806] {CVE-2013-1796}
- tmpfs: fix use-after-free of mempolicy object (Greg Thelen) [Orabug: 16515833] {CVE-2013-1767}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:35.669-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:32.352-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:55.215-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129476"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:128801"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129481"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129672"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129103"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129656"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129298"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129485"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129609"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129171"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129409"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129363"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27453" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0247 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0247.html" ref_id="ELSA-2013-0247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0424" ref_id="CVE-2013-0424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0425" ref_id="CVE-2013-0425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0426" ref_id="CVE-2013-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0427" ref_id="CVE-2013-0427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0428" ref_id="CVE-2013-0428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0429" ref_id="CVE-2013-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0432" ref_id="CVE-2013-0432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0433" ref_id="CVE-2013-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0434" ref_id="CVE-2013-0434"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0435" ref_id="CVE-2013-0435"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0440" ref_id="CVE-2013-0440"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0441" ref_id="CVE-2013-0441"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0442" ref_id="CVE-2013-0442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0443" ref_id="CVE-2013-0443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0445" ref_id="CVE-2013-0445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0450" ref_id="CVE-2013-0450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1475" ref_id="CVE-2013-1475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1476" ref_id="CVE-2013-1476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1478" ref_id="CVE-2013-1478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1480" ref_id="CVE-2013-1480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0431" ref_id="CVE-2013-0431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0444" ref_id="CVE-2013-0444"/>
        <description>[1.7.0.9-2.3.5.3.0.1.el6_3]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.5.3.el6_3]
- Sync logging fixes with upstream (icedtea7-forest and jdk7u)

[1.7.0.9-2.3.5.1.el6_3]
- Removed 6664509 backout and added 8005615 to fix the issue

[1.7.0.9-2.3.5.el6_3.1]
- Backed out 6664509 and 7201064.patch which cause regressions

[1.7.0.9-2.3.5.el6_3]
- Bumped to 2.3.5
- Changed BR to java7-devel >= 1:1.7.0 as required by CORBA changes in 2.3.5
- Resolves: rhbz#906707</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:41.812-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:30.589-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:54.309-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:32:38.184-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:32:38.184-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130455"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130086"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130397"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129513"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130441"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129928"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130423"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130417"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130354"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129835"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27450" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0144 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0144.html" ref_id="ELSA-2013-0144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0744" ref_id="CVE-2013-0744"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0746" ref_id="CVE-2013-0746"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0748" ref_id="CVE-2013-0748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0750" ref_id="CVE-2013-0750"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0753" ref_id="CVE-2013-0753"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0754" ref_id="CVE-2013-0754"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0758" ref_id="CVE-2013-0758"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0759" ref_id="CVE-2013-0759"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0762" ref_id="CVE-2013-0762"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0766" ref_id="CVE-2013-0766"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0767" ref_id="CVE-2013-0767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0769" ref_id="CVE-2013-0769"/>
        <description>firefox
[10.0.12-1.0.1.el6_3]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[10.0.12-1]
- Update to 10.0.12 ESR

xulrunner
[10.0.12-1.0.1.el6_3]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.12-1]
- Update to 10.0.12 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:23.792-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:29.386-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:53.709-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:47:49.489-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:47:49.489-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.12-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130718"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130079"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130496"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.12-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130727"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130303"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130333"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27449" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0165 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0165.html" ref_id="ELSA-2013-0165"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3174" ref_id="CVE-2012-3174"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0422" ref_id="CVE-2013-0422"/>
        <description>[1.7.0.9-2.3.4.1.0.1.el6_3]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.4.1.el6]
- Rewerted to IcedTea 2.3.4
  - rewerted patch105: java-1.7.0-openjdk-disable-system-lcms.patch
  - removed jxmd and idlj to alternatives
  - make NOT executed with   DISABLE_INTREE_EC=true and UNLIMITED_CRYPTO=true
  - re-applied patch302 and restored systemtap.patch
  - buildver set to 9
  - icedtea_version set to 2.3.4
  - unapplied patch112 java-1.7.openjdk-doNotUseDisabledEcc.patch
  - restored tmp-patches source tarball
  - removed /lib/security/US_export_policy.jar and lib/security/local_policy.jar
  - java-1.7.0-openjdk-java-access-bridge-security.patch's path moved from
    java.security-linux back to java.security
- Resolves: rhbz#895033

[1.7.0.11-2.4.0.1.el6]
- Rewritten patch105: java-1.7.0-openjdk-disable-system-lcms.patch
- Added jxmd and idlj to alternatives
- make executed with   DISABLE_INTREE_EC=true and UNLIMITED_CRYPTO=true
- Unapplied patch302 and deleted systemtap.patch
- buildver increased to 11
- icedtea_version set to 2.4.0
- Added and applied patch112 java-1.7.openjdk-doNotUseDisabledEcc.patch
- removed tmp-patches source tarball
- Added /lib/security/US_export_policy.jar and lib/security/local_policy.jar
- Resolves: rhbz#895033</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:48.968-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:29.083-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:53.541-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:29:12.907-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:29:12.907-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130612"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130660"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130470"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130588"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130564"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130645"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129873"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129941"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130650"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27448" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0710 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0710.html" ref_id="ELSA-2012-0710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3101" ref_id="CVE-2011-3101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1937" ref_id="CVE-2012-1937"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1938" ref_id="CVE-2012-1938"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1939" ref_id="CVE-2012-1939"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1940" ref_id="CVE-2012-1940"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1941" ref_id="CVE-2012-1941"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1944" ref_id="CVE-2012-1944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1945" ref_id="CVE-2012-1945"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1946" ref_id="CVE-2012-1946"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1947" ref_id="CVE-2012-1947"/>
        <description>firefox:

[10.0.5-1.0.1.el6_2]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.5-1]
- Update to 10.0.5 ESR

xulrunner:

[10.0.5-1.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.5-1]
- Update to 10.0.5 ESR

[10.0.4-2]
- Added patch for mozbz#703633</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:02.452-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:28.031-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:53.123-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:28:16.533-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:28:16.533-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.5-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131452"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131977"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131962"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.5-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131694"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131343"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27443" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1310 -- samba3x security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1310.html" ref_id="ELSA-2013-1310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213" ref_id="CVE-2013-0213"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214" ref_id="CVE-2013-0214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124" ref_id="CVE-2013-4124"/>
        <description>[3.6.6-0.136]

- resolves: #984807 - CVE-2013-4124: DoS via integer overflow when reading

                      an EA list</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:26.936-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:26.803-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:52.492-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba3x is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:128906"/>
          <criterion comment="samba3x-client is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:129028"/>
          <criterion comment="samba3x-common is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:128940"/>
          <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:129052"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:128804"/>
          <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:128849"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:128791"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.136.el5" test_ref="oval:org.mitre.oval:tst:129037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27441" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1049 -- php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1049.html" ref_id="ELSA-2013-1049"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4113" ref_id="CVE-2013-4113"/>
        <description>[5.3.3-23]
- add security fix for CVE-2013-4113</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:13.399-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:26.122-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:52.062-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:12:51.760-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:12:51.760-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128599"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128899"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129352"/>
            <criterion comment="php-common is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128952"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128815"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129330"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129321"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129325"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129334"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129112"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129331"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128736"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129142"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129295"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129305"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129235"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129285"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129343"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129216"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128920"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129193"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129071"/>
            <criterion comment="php-common is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129250"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129247"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128877"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129081"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128778"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129201"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128889"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129184"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129284"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128709"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129304"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129241"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129139"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128546"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129293"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129314"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129049"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128531"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129009"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129143"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129095"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129126"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128943"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27439" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2021 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2021.html" ref_id="ELSA-2012-2021"/>
        <description>[2.6.39-100.10.1.el6uek]
- thp: avoid atomic64_read in pmd_read_atomic for 32bit PAE (Andrea Arcangeli)
  [Orabug: 14217003]

[2.6.39-100.9.1.el6uek]
- mm: pmd_read_atomic: fix 32bit PAE pmd walk vs pmd_populate SMP race
  condition (Andrea Arcangeli) [Bugdb: 13966] {CVE-2012-2373}
- mm: thp: fix pmd_bad() triggering in code paths holding mmap_sem read mode
  (Andrea Arcangeli)  {CVE-2012-1179}
- KVM: Fix buffer overflow in kvm_set_irq() (Avi Kivity) [Bugdb: 13966]
  {CVE-2012-2137}
- net: sock: validate data_len before allocating skb in sock_alloc_send_pskb()
  (Jason Wang) [Bugdb: 13966] {CVE-2012-2136}
- KVM: lock slots_lock around device assignment (Alex Williamson) [Bugdb:
  13966] {CVE-2012-2121}
- KVM: unmap pages from the iommu when slots are removed (Alex Williamson)
  [Bugdb: 13966] {CVE-2012-2121}
- KVM: introduce kvm_for_each_memslot macro (Xiao Guangrong) [Bugdb: 13966]
- fcaps: clear the same personality flags as suid when fcaps are used (Eric
  Paris) [Bugdb: 13966] {CVE-2012-2123}

[2.6.39-100.8.1.el6uek]
- net: ipv4: relax AF_INET check in bind() (Eric Dumazet) [Orabug: 14054411]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:17.192-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:25.705-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:51.732-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131923"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131904"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131864"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131911"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131213"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131523"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131449"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131866"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131846"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131011"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131624"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131532"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27438" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0168 -- httpd security and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0168.html" ref_id="ELSA-2010-0168"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408" ref_id="CVE-2010-0408"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0434" ref_id="CVE-2010-0434"/>
        <description>[2.2.3-31.0.1.el5_4.4]
- Replace index.html with Oracle's index page oracle_index.html
- Update vstring and distro in specfile

[2.2.3-31.4]
- require and BR a version of OpenSSL with the secure reneg API (#567980)

[2.2.3-31.3]
- mod_ssl: add SSLInsecureRenegotiation (#567980)
- add security fixes for CVE-2010-0408, CVE-2010-0434 (#570440)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:08.569-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:25.366-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:51.528-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:54:53.990-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:54:53.990-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd is earlier than 0:2.2.3-31.0.1.el5_4.4" test_ref="oval:org.mitre.oval:tst:135194"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-31.0.1.el5_4.4" test_ref="oval:org.mitre.oval:tst:135158"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.3-31.0.1.el5_4.4" test_ref="oval:org.mitre.oval:tst:135093"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-31.0.1.el5_4.4" test_ref="oval:org.mitre.oval:tst:135091"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27436" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-0305 -- boost security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>boost</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0305.html" ref_id="ELSA-2012-0305"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0171" ref_id="CVE-2008-0171"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0172" ref_id="CVE-2008-0172"/>
        <description>[1.33.1-15]
- Fix bugs in parsing invalid regexps
- Resolves: #766755

[1.33.1-14]
- Delete leftover .orig files after patches are successfully applied

[1.33.1-13]
- GCC 4.4 fixes
- Resolves: #567722

[1.33.1-11]
- Add a fix for thread safety bug in boost::regex
- Build with -fno-strict-aliasing due to the sheer amount of warnings
  that we get.
- Resolves: #472384</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:05.246-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:25.025-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:51.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="boost is earlier than 0:1.33.1-15.el5" test_ref="oval:org.mitre.oval:tst:132129"/>
          <criterion comment="boost-devel is earlier than 0:1.33.1-15.el5" test_ref="oval:org.mitre.oval:tst:132363"/>
          <criterion comment="boost-doc is earlier than 0:1.33.1-15.el5" test_ref="oval:org.mitre.oval:tst:132442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27435" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1540 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1540.html" ref_id="ELSA-2012-1540"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2372" ref_id="CVE-2012-2372"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3552" ref_id="CVE-2012-3552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4508" ref_id="CVE-2012-4508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4535" ref_id="CVE-2012-4535"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4537" ref_id="CVE-2012-4537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5513" ref_id="CVE-2012-5513"/>
        <description>kernel
[2.6.18-308.24.1.el5]
- Revert: [scsi] sg: fix races during device removal (Ewan Milne) [868950 861004]

[2.6.18-308.23.1.el5]
- [net] bnx2x: Add remote-fault link detection (Alexander Gordeev) [870120 796905]
- [net] bnx2x: Cosmetic changes (Alexander Gordeev) [870120 796905]
- [net] rds-ping cause kernel panic (Alexander Gordeev) [822755 822756] {CVE-2012-2372}
- [xen] add guest address range checks to XENMEM_exchange handlers (Igor Mammedov) [878033 878034] {CVE-2012-5513}
- [xen] x86/physmap: Prevent incorrect updates of m2p mappings (Igor Mammedov) [870148 870149] {CVE-2012-4537}
- [xen] VCPU/timer: Dos vulnerability prev overflow in calculations (Igor Mammedov) [870150 870151] {CVE-2012-4535}
- [scsi] sg: fix races during device removal (Ewan Milne) [868950 861004]

[2.6.18-308.22.1.el5]
- [net] bonding: fix link down handling in 802.3ad mode (Andy Gospodarek) [877943 782866]

[2.6.18-308.21.1.el5]
- [fs] ext4: race-cond protect for convert_unwritten_extents_endio (Lukas Czerner) [869910 869911] {CVE-2012-4508}
- [fs] ext4: serialize fallocate w/ ext4_convert_unwritten_extents (Lukas Czerner) [869910 869911] {CVE-2012-4508}
- [fs] ext4: flush the i_completed_io_list during ext4_truncate (Lukas Czerner) [869910 869911] {CVE-2012-4508}
- [net] WARN if struct ip_options was allocated directly by kmalloc (Jiri Pirko) [874973 872612]
- [net] ipv4: add RCU protection to inet->opt (Jiri Pirko) [872113 855302] {CVE-2012-3552}
- [scsi] qla2xx: Dont toggle inter bits after IRQ lines attached (Chad Dupuis) [870118 800708]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:43.180-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:24.804-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:51.103-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:17:55.938-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:17:55.938-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130811"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.24.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130786"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.24.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130764"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130629"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130812"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130687"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130646"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130578"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130515"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130378"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130853"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:130565"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.24.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130560"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.24.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129859"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.24.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130765"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.24.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130664"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.24.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130777"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.24.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130605"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27434" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0533 -- samba and samba3x security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0533.html" ref_id="ELSA-2012-0533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2111" ref_id="CVE-2012-2111"/>
        <description>[3.5.10-116]
- Security Release, fixes CVE-2012-2111
- resolves: #815688</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:28.696-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:24.488-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:50.911-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:23:20.888-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:23:20.888-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132323"/>
            <criterion comment="samba3x-client is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132094"/>
            <criterion comment="samba3x-common is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132339"/>
            <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:131989"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132309"/>
            <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132417"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:131873"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:131926"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132195"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132375"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132181"/>
            <criterion comment="samba-client is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132407"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:131503"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132462"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132289"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132039"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132263"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132313"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132176"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132411"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27433" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2537 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2537.html" ref_id="ELSA-2013-2537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" ref_id="CVE-2013-0914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" ref_id="CVE-2013-3222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" ref_id="CVE-2013-3224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6548" ref_id="CVE-2012-6548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2634" ref_id="CVE-2013-2634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2852" ref_id="CVE-2013-2852"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3225" ref_id="CVE-2013-3225"/>
        <description>kernel-uek
[2.6.32-400.29.2uek]
- Bluetooth: RFCOMM - Fix missing msg_namelen update in rfcomm_sock_recvmsg() (Mathias Krause) [Orabug: 17173824] {CVE-2013-3225}
- Bluetooth: fix possible info leak in bt_sock_recvmsg() (Mathias Krause) [Orabug: 17173824] {CVE-2013-3224}
- atm: update msg_namelen in vcc_recvmsg() (Mathias Krause) [Orabug: 17173824] {CVE-2013-3222}
- dcbnl: fix various netlink info leaks (Mathias Krause) [Orabug: 17173824] {CVE-2013-2634}
- udf: avoid info leak on export (Mathias Krause) [Orabug: 17173824] {CVE-2012-6548}
- b43: stop format string leaking into error msgs (Kees Cook) [Orabug: 17173824] {CVE-2013-2852}
- signal: always clear sa_restorer on execve (Kees Cook) [Orabug: 17173824] {CVE-2013-0914}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:21.500-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:23.995-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:50.647-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35528 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:00.217-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:20.441-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:128820"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129132"/>
            <criterion comment="ofa-2.6.32-400.29.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129261"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129203"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129121"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129165"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129237"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129136"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129269"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129278"/>
            <criterion comment="ofa-2.6.32-400.29.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129168"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128495"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128672"/>
            <criterion comment="ofa-2.6.32-400.29.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129054"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128933"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:129195"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128934"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:129274"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128848"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:129116"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128793"/>
            <criterion comment="ofa-2.6.32-400.29.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129255"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27431" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2584 -- Unbreakable Enterprise Kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2584.html" ref_id="ELSA-2013-2584"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" ref_id="CVE-2012-6545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" ref_id="CVE-2013-3231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1928" ref_id="CVE-2013-1928"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2889" ref_id="CVE-2013-2889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2892" ref_id="CVE-2013-2892"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4387" ref_id="CVE-2013-4387"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4592" ref_id="CVE-2013-4592"/>
        <description>[2.6.39-400.211.2]
- fs/compat_ioctl.c: VIDEO_SET_SPU_PALETTE missing error check (Kees Cook) [Orabug: 17842208] {CVE-2013-1928}
- Bluetooth: RFCOMM - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17842129] {CVE-2012-6545}
- Bluetooth: RFCOMM - Fix info leak in ioctl(RFCOMMGETDEVLIST) (Mathias Krause) [Orabug: 17842105] {CVE-2012-6545}
- llc: Fix missing msg_namelen update in llc_ui_recvmsg() (Mathias Krause) [Orabug: 17842095] {CVE-2013-3231}
- HID: pantherlord: validate output report details (Kees Cook) [Orabug: 17842084] {CVE-2013-2892}
- HID: zeroplus: validate output report details (Kees Cook) [Orabug: 17842081] {CVE-2013-2889}
- HID: provide a helper for validating hid reports (Kees Cook) [Orabug: 17842081] {CVE-2013-2889}
- KVM: Fix iommu map/unmap to handle memory slot moves (Jerry Snitselaar) [Orabug: 17842075] {CVE-2013-4592}
- ansi_cprng: Fix off by one error in non-block size request (Jerry Snitselaar) [Orabug: 17842072] {CVE-2013-4345}
- HID: validate HID report id size (Kees Cook) [Orabug: 17842063] {CVE-2013-2888}
- ipv6: remove max_addresses check from ipv6_create_tempaddr (Hannes Frederic Sowa) [Orabug: 17842056] {CVE-2013-0343}
- ipv6: udp packets following an UFO enqueued packet need also be handled by UFO (Hannes Frederic Sowa) [Orabug: 17842050] {CVE-2013-4387}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:53.256-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:23.336-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:50.111-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128420"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128175"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128485"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128397"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:127806"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128468"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128453"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128170"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128437"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128173"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:127888"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128441"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27430" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1590 -- libtiff security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1590.html" ref_id="ELSA-2012-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3401" ref_id="CVE-2012-3401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4447" ref_id="CVE-2012-4447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4564" ref_id="CVE-2012-4564"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5581" ref_id="CVE-2012-5581"/>
        <description>[3.9.4-9]
- Still more fixes to make test case for CVE-2012-5581 work on all platforms
Resolves: #885310

[3.9.4-8]
- Fix incomplete patch for CVE-2012-3401
- Add libtiff-tiffinfo-exif.patch so that our test case for CVE-2012-5581 works
  with pre-4.0.2 libtiff
Resolves: #885310

[3.9.4-7]
- Add fixes for CVE-2012-3401, CVE-2012-4447, CVE-2012-4564, CVE-2012-5581
Resolves: #885310</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:38.010-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:22.915-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.848-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:18:11.334-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:18:11.334-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:130813"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:130436"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:130380"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:129947"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:130431"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27428" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1459 -- gnupg2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1459.html" ref_id="ELSA-2013-1459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6085" ref_id="CVE-2012-6085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4351" ref_id="CVE-2013-4351"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4402" ref_id="CVE-2013-4402"/>
        <description>[2.0.14-6]
- fix CVE-2013-4351 gpg treats no-usage-permitted keys as all-usages-permitted

[2.0.14-5]
- fix CVE-2012-6085 GnuPG: read_block() corrupt key input validation
- fix CVE-2013-4402 GnuPG: infinite recursion in the compressed packet parser</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:01.310-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:22.195-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.425-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:38:42.583-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:38:42.583-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:128570"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:128235"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:128730"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27426" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1409 -- xinetd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1409.html" ref_id="ELSA-2013-1409"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4342" ref_id="CVE-2013-4342"/>
        <description>[2:2.3.14-39]
- Honor user and group directives
- Resolves: CVE-2013-4342</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:15.555-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:21.661-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.177-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:14:50.037-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:14:50.037-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xinetd is earlier than 0:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:129023"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="xinetd is earlier than 0:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:128919"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27425" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-1166-1 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1166-1.html" ref_id="ELSA-2013-1166-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2147" ref_id="CVE-2013-2147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2164" ref_id="CVE-2013-2164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" ref_id="CVE-2013-2206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2224" ref_id="CVE-2013-2224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" ref_id="CVE-2013-2232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" ref_id="CVE-2013-2234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" ref_id="CVE-2013-2237"/>
        <description>kernel
[2.6.18-348.16.1.0.1]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:22.668-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:21.294-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:48.968-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27425 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:03.312-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:19.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129076"/>
          <criterion comment="ocfs2-2.6.18-348.16.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128902"/>
          <criterion comment="oracleasm-2.6.18-348.16.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128369"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128945"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129125"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128721"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129196"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129173"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128946"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129162"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128507"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.16.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129220"/>
          <criterion comment="ocfs2-2.6.18-348.16.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128731"/>
          <criterion comment="ocfs2-2.6.18-348.16.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128833"/>
          <criterion comment="ocfs2-2.6.18-348.16.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129223"/>
          <criterion comment="oracleasm-2.6.18-348.16.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128928"/>
          <criterion comment="oracleasm-2.6.18-348.16.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128780"/>
          <criterion comment="oracleasm-2.6.18-348.16.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128492"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27424" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0126 -- squirrelmail security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0126.html" ref_id="ELSA-2013-0126"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2124" ref_id="CVE-2012-2124"/>
        <description>[1.4.8-21.0.2.el5]

- remove Redhat splash screen images from source</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:42.134-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:21.121-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:48.880-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:29:06.642-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:29:06.642-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="squirrelmail is earlier than 0:1.4.8-21.0.2.el5" test_ref="oval:org.mitre.oval:tst:130179"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27423" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0147 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0147.html" ref_id="ELSA-2010-0147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4308" ref_id="CVE-2009-4308"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0003" ref_id="CVE-2010-0003"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0007" ref_id="CVE-2010-0007"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0008" ref_id="CVE-2010-0008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0415" ref_id="CVE-2010-0415"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0437" ref_id="CVE-2010-0437"/>
        <description>[2.6.18-164.15.1.0.1.el5]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- Add entropy support to igb ( John Sobecki) [orabug 7607479]
- [nfs] convert ENETUNREACH to ENOTCONN  [orabug 7689332]
- [NET] Add xen pv/bonding  netconsole support (Tina yang) [orabug 6993043]
  [bz 7258]
- [MM] shrink zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [nfsd] fix failure of file creation from hpux client (Wen gang Wang)
  [orabug 7579314]
- FP register state is corrupted during the handling a SIGSEGV (Chuck Anderson)
  [orabug 7708133]
- [x86_64] PCI space below 4GB forces mem remap above 1TB (Larry Woodman) 
  [523522]
- [cpufreq] P-state limit: limit can never be increased (Stanislaw Gruszka) 
  [489566]
- [rds] patch rds to 4.0-ora-1.4.2-10 (Andy Grover, Tina Yang)
  [orabug 9168046] [RHBZ 546374]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:12.021-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:20.529-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:48.442-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:16:27.968-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:16:27.968-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:134978"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.15.1.0.1.el5-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:134289"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.15.1.0.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135179"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135191"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135201"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135269"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135068"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135116"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135064"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135094"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135202"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.15.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:135243"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.15.1.0.1.el5PAE-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:134877"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.15.1.0.1.el5debug-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135190"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-164.15.1.0.1.el5xen-1.4.4-1.el5" test_ref="oval:org.mitre.oval:tst:135167"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.15.1.0.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:134837"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.15.1.0.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135101"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-164.15.1.0.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:135085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27419" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0468 -- libtiff security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0468.html" ref_id="ELSA-2012-0468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1173" ref_id="CVE-2012-1173"/>
        <description>[3.9.4-5]
- Add fix for CVE-2012-1173
Resolves: #CVE-2012-1173</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:27.812-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:18.928-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:47.581-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:02:17.880-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:02:17.880-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:132099"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:132492"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:132294"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:132487"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:132430"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27418" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1307 -- php53 security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1307.html" ref_id="ELSA-2013-1307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1398" ref_id="CVE-2011-1398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0831" ref_id="CVE-2012-0831"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2688" ref_id="CVE-2012-2688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7243" ref_id="CVE-2006-7243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1643" ref_id="CVE-2013-1643"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4248" ref_id="CVE-2013-4248"/>
        <description>[5.3.3-21]

- add security fix for CVE-2013-4248</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:23.967-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:18.065-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:47.243-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:08:04.615-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:08:04.615-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php53 is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:129002"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:129109"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128351"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128596"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128803"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128241"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:129045"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128977"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128873"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128621"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128948"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128809"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:129075"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128863"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128969"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128705"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128324"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128738"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:129032"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128592"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:128840"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27417" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1213 -- gdm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gdm</product>
          <product>initscripts</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1213.html" ref_id="ELSA-2013-1213"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4169" ref_id="CVE-2013-4169"/>
        <description>gdm
[2.16.0-59.0.1.el5_9.1]
- Fix gdmconfig memory leaks [orabug 12734629]

[2.16.0-59.1]
- Don't try to pre-create directories that are internal
  implementation details of X.
  Resolves: #997619 CVE-2013-4169

initscripts
[8.45.42-2.0.1.el5_9.1]
- Do not rename eth devices. Orabug 14266688.
  Apply upstream patches:
  0001-Remove-reference-to-rename_device.patch
  0002-rename_device-dequote-DEVICE-eth0.patch
  0003-dont_try_to_rename_devices.patch
- change the ifup-eth and ifdown-eth script to use default leases file of dhclient. [Orabug 12434590]
- Update oracle-enterprise.patch to do detection on /etc/oracle-release
  and /etc/enterprise-release
- Patch x86_64 sysctl.conf as well as default sysctl.conf
- Patch sysctl.conf to default rp_filter to loose reverse path
  filtering (has no effect for pre-2.6.32 kernels) [orabug 10286227]
- Move hwclock into udev rules
- Update oracle-enterprise.patch to fix RedHat references in arch specific
  sysctl.conf files in source tarball
- Add oracle-enterprise.patch and update specfile
- Don't attempt to re-enslave already-enslaved devices (#455537) (pknirsch@redhat.com)

[8.45.42-2.1]
- create /tmp/.X11-unix in rc.sysinit (#997622, CVE-2013-4169)

[8.45.42-2]
- added missing '-p p' for kpartx in netfs (#844671)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:28.567-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:17.823-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:47.115-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:05:49.757-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:05:49.757-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gdm is earlier than 0:2.16.0-59.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:128884"/>
          <criterion comment="initscripts is earlier than 0:8.45.42-2.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:128191"/>
          <criterion comment="gdm-docs is earlier than 0:2.16.0-59.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:129030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27415" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0698 -- samba3x security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0698.html" ref_id="ELSA-2010-0698"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3069" ref_id="CVE-2010-3069"/>
        <description>[3.3.8-0.52.2]
- Security Release, fixes CVE-2010-3069
- resolves: #632231</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:10.918-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:17.502-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.917-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:36:41.515-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:36:41.515-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba3x is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134910"/>
          <criterion comment="libtalloc is earlier than 0:1.2.0-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134665"/>
          <criterion comment="libtalloc-devel is earlier than 0:1.2.0-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134810"/>
          <criterion comment="libtdb is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:135014"/>
          <criterion comment="libtdb-devel is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134237"/>
          <criterion comment="samba3x-client is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134569"/>
          <criterion comment="samba3x-common is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134256"/>
          <criterion comment="samba3x-doc is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134848"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134834"/>
          <criterion comment="samba3x-swat is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134982"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134941"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134736"/>
          <criterion comment="tdb-tools is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:134960"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27413" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2588 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2588.html" ref_id="ELSA-2013-2588"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4470" ref_id="CVE-2013-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6367" ref_id="CVE-2013-6367"/>
        <description>[2.6.39-400.211.3]
- ip6_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951806] {CVE-2013-4470}
- ip_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951818] {CVE-2013-4470}
- KVM: x86: Fix potential divide by 0 in lapic (CVE-2013-6367) (Andy Honig) [Orabug: 17951705] {CVE-2013-6367}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:49.014-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:17.050-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127411"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:128157"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127349"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:128243"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127711"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127358"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:127387"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:127390"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128310"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128189"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128162"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128019"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27412" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1156 -- httpd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1156.html" ref_id="ELSA-2013-1156"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1896" ref_id="CVE-2013-1896"/>
        <description>[2.2.15-29.0.1.el6_4]
- replace index.html with Oracle's index page oracle_index.html
  update vstring in specfile

[2.2.15-29]
- mod_dav: add security fix for CVE-2013-1896 (#991368)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:14.910-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:16.801-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.464-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:20:36.244-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:20:36.244-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128888"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128676"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129264"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129243"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128972"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129219"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128861"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129240"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129119"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27411" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1411 -- glibc security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1411.html" ref_id="ELSA-2013-1411"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4332" ref_id="CVE-2013-4332"/>
        <description>[2.5-118.2]
- Fix integer overflows in *valloc and memalign. (#1011804).

[2.5-118.1]
- Add support for newer L3 caches on x86-64 and correctly count
  the number of hardware threads sharing a cacheline (#1011424).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:22.646-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:16.545-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.368-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:28:39.064-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:28:39.064-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:128810"/>
          <criterion comment="glibc-common is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:128577"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:128095"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:129061"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:128903"/>
          <criterion comment="nscd is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:128896"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27410" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0127 -- libvirt security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0127.html" ref_id="ELSA-2013-0127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2693" ref_id="CVE-2012-2693"/>
        <description>[0.8.2-29.0.1.el5]

- Replaced docs/et.png in tarball

- remove virshtest from test cases to fix failure in mock build root</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:48.341-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:16.367-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.268-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:39:36.720-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:39:36.720-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.8.2-29.0.1.el5" test_ref="oval:org.mitre.oval:tst:130597"/>
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-29.0.1.el5" test_ref="oval:org.mitre.oval:tst:129964"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.2-29.0.1.el5" test_ref="oval:org.mitre.oval:tst:130412"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27408" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0097 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0097.html" ref_id="ELSA-2014-0097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5878" ref_id="CVE-2013-5878"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5884" ref_id="CVE-2013-5884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5896" ref_id="CVE-2013-5896"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5907" ref_id="CVE-2013-5907"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5910" ref_id="CVE-2013-5910"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0368" ref_id="CVE-2014-0368"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0373" ref_id="CVE-2014-0373"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0376" ref_id="CVE-2014-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0411" ref_id="CVE-2014-0411"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0416" ref_id="CVE-2014-0416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0422" ref_id="CVE-2014-0422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0423" ref_id="CVE-2014-0423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0428" ref_id="CVE-2014-0428"/>
        <description>[1:1.6.0.1-3.1.13.0]
- updated to icedtea 1.13.1
 - http://blog.fuseyism.com/index.php/2014/01/23/security-icedtea-1-12-8-1-13-1-for-openjdk-6-released/
- updated to jdk6, b30,  21_jan_2014
 - https://openjdk6.java.net/OpenJDK6-B30-Changes.html
- adapted patch7 1.13_fixes.patch
- pre 2011 changelog moved to (till now  wrong) pre-2009-spec-changelog (rh1043611)
- added --disable-system-lcms to configure options to pass build
- adapted patch3 java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#1050190</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:44.722-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:15.107-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:45.959-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:01:37.243-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:01:37.243-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127676"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128023"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127671"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128210"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128002"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128096"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:127928"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128161"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128205"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128198"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27406" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1220 -- samba3x security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1220.html" ref_id="ELSA-2011-1220"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1678" ref_id="CVE-2011-1678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2522" ref_id="CVE-2011-2522"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2694" ref_id="CVE-2011-2694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2724" ref_id="CVE-2011-2724"/>
        <description>[3.5.4-0.83.2]
- Security Release, add fix for CVE-2011-2724
- related: #722555

[3.5.4-0.83.1]
- Security Release, fixes CVE-2011-2694, CVE-2011-2522, CVE-2011-1678
- resolves: #722555</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:38.731-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:14.435-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:45.497-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:45:23.436-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:45:23.436-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba3x is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:133488"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:133455"/>
          <criterion comment="samba3x-common is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:133552"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:132989"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:133171"/>
          <criterion comment="samba3x-swat is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:133106"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:133517"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.4-0.83.el5_7.2" test_ref="oval:org.mitre.oval:tst:133395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27403" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0130 -- httpd security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0130.html" ref_id="ELSA-2013-0130"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0455" ref_id="CVE-2008-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0456" ref_id="CVE-2008-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2687" ref_id="CVE-2012-2687"/>
        <description>[2.2.3-74.0.1.el5]

- fix mod_ssl always performing full renegotiation (Joe Jin) [orabug 12423387]

- replace index.html with Oracle's index page oracle_index.html

- update vstring and distro in specfile



[2.2.3-74]

- further %post scriptlet fix (#752618, #867736)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:49.710-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:13.729-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.996-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:30:17.886-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:30:17.886-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd is earlier than 0:2.2.3-74.0.1.el5" test_ref="oval:org.mitre.oval:tst:130312"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-74.0.1.el5" test_ref="oval:org.mitre.oval:tst:130569"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.3-74.0.1.el5" test_ref="oval:org.mitre.oval:tst:130293"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-74.0.1.el5" test_ref="oval:org.mitre.oval:tst:130524"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27401" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1268 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1268.html" ref_id="ELSA-2013-1268"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718" ref_id="CVE-2013-1718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722" ref_id="CVE-2013-1722"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725" ref_id="CVE-2013-1725"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730" ref_id="CVE-2013-1730"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732" ref_id="CVE-2013-1732"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735" ref_id="CVE-2013-1735"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736" ref_id="CVE-2013-1736"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737" ref_id="CVE-2013-1737"/>
        <description>firefox
[17.0.9-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.9-1]
- Update to 17.0.9 ESR

[17.0.8-4]
- Added fix for mozbz#601442 - Support the extensions.getAddons.showPane
  pref again in the Add-ons Manager UI, a part of rhbz#818636 fix.

[17.0.8-3]
- Fixed rhbz#818636 - Firefox allows install of addons,
  disregarding xpinstall.enabled flag set as false.

[17.0.8-2]
- Updated manual page

xulrunner
[17.0.9-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.9-1]
- Update to 17.0.9 ESR

[17.0.8-5]
- Fixed mozbz#633001 - Cannot open ipv6 address with self-signed certificate

[17.0.8-4]
- Fixed rhbz#818636 - Firefox allows install of addons,
  disregarding xpinstall.enabled flag set as false.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:55.235-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:13.293-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.720-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:02:25.345-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:02:25.345-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128975"/>
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128755"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129087"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128136"/>
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128426"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27398" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0108 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0108.html" ref_id="ELSA-2014-0108"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4494" ref_id="CVE-2013-4494"/>
        <description>kernel
[2.6.18-371.4.1]
- [char] ipmi: fix message handling during panics (Tony Camuso) [1049731 995293]
- [net] igb: Use 32bit mask calculating the flow control watermarks (Stefan Assmann) [1041694 1036115]
- [fs] NTLM auth and sign - Use appropriate server challenge (Sachin Prabhu) [1029865 1018286]
- [xen] gnttab: correct locking order reversal (Radim Krcmar) [1026245 1026246] {CVE-2013-4494}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:21.791-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:12.562-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.235-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:56:11.262-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:56:11.262-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:128089"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.4.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127737"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.4.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128180"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:127812"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:128139"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:128178"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:127953"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:128167"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:128166"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:128187"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:127892"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:127420"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.4.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128172"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.4.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127809"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.4.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128088"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.4.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127857"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.4.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127617"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.4.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128181"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27396" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1269 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1269.html" ref_id="ELSA-2013-1269"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718" ref_id="CVE-2013-1718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722" ref_id="CVE-2013-1722"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725" ref_id="CVE-2013-1725"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730" ref_id="CVE-2013-1730"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732" ref_id="CVE-2013-1732"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735" ref_id="CVE-2013-1735"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736" ref_id="CVE-2013-1736"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737" ref_id="CVE-2013-1737"/>
        <description>[17.0.9-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.9-1]
- Update to 17.0.9 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:21.601-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:11.601-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:43.589-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:42:29.985-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:42:29.985-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128858"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128433"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27394" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1081 -- sudo security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1081.html" ref_id="ELSA-2012-1081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2337" ref_id="CVE-2012-2337"/>
        <description>[1.7.4p5-12]
- added patch for CVE-2012-2337
  Resolves: rhbz#829756</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:31.160-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:10.998-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:42.872-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:53:41.846-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:53:41.846-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8" test_ref="oval:org.mitre.oval:tst:131475"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="sudo is earlier than 0:1.7.4p5-12.el6_3" test_ref="oval:org.mitre.oval:tst:131238"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27393" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1326 -- pango security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pango</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1326.html" ref_id="ELSA-2011-1326"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3193" ref_id="CVE-2011-3193"/>
        <description>[1.14.9.8.0.1.el5_7.3]
- Bump release

[1.14.9.8.el5_1.3]
- Prevent buffer overflow errors in harfbuzz module (CVE-2011-3193)
- Resolves: #737819</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:08.415-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:10.823-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:42.714-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:46:48.581-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:46:48.581-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pango is earlier than 0:1.14.9-8.0.1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133534"/>
          <criterion comment="pango-devel is earlier than 0:1.14.9-8.0.1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133482"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27391" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0448 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0448.html" ref_id="ELSA-2014-0448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1518" ref_id="CVE-2014-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1523" ref_id="CVE-2014-1523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1524" ref_id="CVE-2014-1524"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1529" ref_id="CVE-2014-1529"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1530" ref_id="CVE-2014-1530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1531" ref_id="CVE-2014-1531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1532" ref_id="CVE-2014-1532"/>
        <description>[24.5.0-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.5.0-1]
- Update to 24.5.0 ESR

[24.4.0-3]
- Added a workaround for Bug 1054242 - RHEVM: Extremely high memory
  usage in Firefox 24 ESR on RHEL 6.5

[24.4.0-2]
- fixed rhbz#1067343 - Broken languagepack configuration
  after firefox update</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:34.964-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:09.931-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:42.252-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:38:24.547-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:38:24.547-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127560"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27390" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0898 -- mesa security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mesa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0898.html" ref_id="ELSA-2013-0898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1993" ref_id="CVE-2013-1993"/>
        <description>[6.5.1-7.11]
- CVE-2013-1993 - buffer overflows in DRI protocol (#963066)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:29.792-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:09.710-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:42.064-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:53:06.621-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:53:06.621-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mesa is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129232"/>
          <criterion comment="glx-utils is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129501"/>
          <criterion comment="mesa-libGL is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:128550"/>
          <criterion comment="mesa-libGL-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129376"/>
          <criterion comment="mesa-libGLU is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:128606"/>
          <criterion comment="mesa-libGLU-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129504"/>
          <criterion comment="mesa-libGLw is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129370"/>
          <criterion comment="mesa-libGLw-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129129"/>
          <criterion comment="mesa-libOSMesa is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129507"/>
          <criterion comment="mesa-libOSMesa-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129245"/>
          <criterion comment="mesa-source is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:129212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27384" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1292 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1292.html" ref_id="ELSA-2013-1292"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3511" ref_id="CVE-2012-3511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2141" ref_id="CVE-2013-2141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4162" ref_id="CVE-2013-4162"/>
        <description>kernel
[2.6.18-348.18.1]
- [net] be2net: enable polling prior enabling interrupts globally (Ivan Vecera) [1005239 987539]
- [kernel] signals: stop info leak via tkill and tgkill syscalls (Oleg Nesterov) [970874 970875] {CVE-2013-2141}
- [net] ipv6: do udp_push_pending_frames AF_INET sock pending data (Jiri Benc) [987647 987648] {CVE-2013-4162}
- [mm] use-after-free in madvise_remove() (Jacob Tanenbaum) [849735 849736] {CVE-2012-3511}
- [fs] autofs: remove autofs dentry mount check (Ian Kent) [1001488 928098]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:58.217-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:07.148-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:40.470-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:40:04.899-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:40:04.899-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:128837"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.18.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129084"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.18.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128905"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:129065"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:128246"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:129043"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:128134"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:129010"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:128728"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:128910"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:129060"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:128702"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.18.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128828"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.18.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128947"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.18.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128989"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.18.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128941"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.18.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128626"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.18.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128786"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27383" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2538 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2538.html" ref_id="ELSA-2013-2538"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" ref_id="CVE-2013-0914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" ref_id="CVE-2013-3222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" ref_id="CVE-2013-3224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6548" ref_id="CVE-2012-6548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2634" ref_id="CVE-2013-2634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2635" ref_id="CVE-2013-2635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2852" ref_id="CVE-2013-2852"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3225" ref_id="CVE-2013-3225"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3301" ref_id="CVE-2013-3301"/>
        <description>[2.6.39-400.109.3]
- Revert 'be2net: enable interrupts in probe' (Jerry Snitselaar) [Orabug: 17179597]

[2.6.39-400.109.2]
- be2net: enable interrupts in probe (Jerry Snitselaar) [Orabug: 17080364] 
- Bluetooth: RFCOMM - Fix missing msg_namelen update in rfcomm_sock_recvmsg() (Mathias Krause) [Orabug: 17173830] {CVE-2013-3225}
- Bluetooth: fix possible info leak in bt_sock_recvmsg() (Mathias Krause) [Orabug: 17173830] {CVE-2013-3224}
- atm: update msg_namelen in vcc_recvmsg() (Mathias Krause) [Orabug: 17173830] {CVE-2013-3222}
- rtnl: fix info leak on RTM_GETLINK request for VF devices (Mathias Krause) [Orabug: 17173830] {CVE-2013-2635}
- dcbnl: fix various netlink info leaks (Mathias Krause) [Orabug: 17173830] {CVE-2013-2634}
- udf: avoid info leak on export (Mathias Krause) [Orabug: 17173830] {CVE-2012-6548}
- tracing: Fix possible NULL pointer dereferences (Namhyung Kim) [Orabug: 17173830] {CVE-2013-3301}
- b43: stop format string leaking into error msgs (Kees Cook) [Orabug: 17173830] {CVE-2013-2852}
- signal: always clear sa_restorer on execve (Kees Cook) [Orabug: 17173830] {CVE-2013-0914}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:38.113-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:06.205-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:40.032-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129159"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129077"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129258"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129022"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129147"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:128993"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:128924"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:129202"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:128950"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:129213"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:129279"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:128551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27381" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-1449-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1449-1.html" ref_id="ELSA-2013-1449-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4368" ref_id="CVE-2013-4368"/>
        <description>kernel
[2.6.18-371.1.2.0.1]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:05.327-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:05.085-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:39.507-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35105 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:58.100-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:18.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128879"/>
          <criterion comment="ocfs2-2.6.18-371.1.2.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128878"/>
          <criterion comment="oracleasm-2.6.18-371.1.2.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128875"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128567"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128581"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128317"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:127890"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128203"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128822"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128630"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128556"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.1.2.0.1.el5" test_ref="oval:org.mitre.oval:tst:128249"/>
          <criterion comment="ocfs2-2.6.18-371.1.2.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128530"/>
          <criterion comment="ocfs2-2.6.18-371.1.2.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128823"/>
          <criterion comment="ocfs2-2.6.18-371.1.2.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128226"/>
          <criterion comment="oracleasm-2.6.18-371.1.2.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128555"/>
          <criterion comment="oracleasm-2.6.18-371.1.2.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128681"/>
          <criterion comment="oracleasm-2.6.18-371.1.2.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128400"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27378" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2575 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2575.html" ref_id="ELSA-2013-2575"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4162" ref_id="CVE-2013-4162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <description>kernel-uek
[2.6.32-400.33.2]
- dm snapshot: fix data corruption (Mikulas Patocka) [Orabug: 17618900] {CVE-2013-4299}
- ipv6: call udp_push_pending_frames when uncorking a socket with AF_INET pending data (Hannes Frederic Sowa) [Orabug: 17618897] {CVE-2013-4162}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:17.471-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:04.133-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:39.117-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35446 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:56.196-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:18.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128860"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129025"/>
            <criterion comment="ofa-2.6.32-400.33.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128995"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128254"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128987"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128148"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128679"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128911"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128846"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128915"/>
            <criterion comment="ofa-2.6.32-400.33.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128957"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128829"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128482"/>
            <criterion comment="ofa-2.6.32-400.33.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128956"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128396"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128998"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128882"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:129055"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128575"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128529"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128869"/>
            <criterion comment="ofa-2.6.32-400.33.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27376" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0163 -- kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0163.html" ref_id="ELSA-2014-0163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6367" ref_id="CVE-2013-6367"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6368" ref_id="CVE-2013-6368"/>
        <description>[kvm-83-266.0.1.el5_10.1]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch

[kvm-83-266_10.1.el5]
- KVM: x86: prevent cross page vapic_addr access (CVE-2013-6368) [bz#1032219]
- KVM: x86: Fix potential divide by 0 in lapic (CVE-2013-6367) [bz#1032216]
- Resolves: bz#1032219
  (CVE-2013-6368 kvm: cross page vapic_addr access [rhel-5.10])
- Resolves: bz#1032216
  CVE-2013-6367 kvm: division by zero in apic_get_tmcct() [rhel-5.10.z]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:36.543-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:03.727-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:38.844-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:14:00.293-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:14:00.293-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-266.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:127994"/>
          <criterion comment="kmod-kvm is earlier than 0:83-266.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:127950"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-266.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:127729"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-266.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:127915"/>
          <criterion comment="kvm-tools is earlier than 0:83-266.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:127739"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27375" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-1540-1 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1540-1.html" ref_id="ELSA-2012-1540-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2372" ref_id="CVE-2012-2372"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3552" ref_id="CVE-2012-3552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4508" ref_id="CVE-2012-4508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4535" ref_id="CVE-2012-4535"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4537" ref_id="CVE-2012-4537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5513" ref_id="CVE-2012-5513"/>
        <description>kernel
[2.6.18-308.24.1.0.1.el5]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printks when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:47.159-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:03.156-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:38.425-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35596 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:59.880-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:17.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130774"/>
          <criterion comment="ocfs2-2.6.18-308.24.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130180"/>
          <criterion comment="oracleasm-2.6.18-308.24.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130616"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130323"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130621"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130818"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130824"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130833"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130498"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130835"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130771"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.24.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130617"/>
          <criterion comment="ocfs2-2.6.18-308.24.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130758"/>
          <criterion comment="ocfs2-2.6.18-308.24.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130667"/>
          <criterion comment="ocfs2-2.6.18-308.24.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130213"/>
          <criterion comment="oracleasm-2.6.18-308.24.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130531"/>
          <criterion comment="oracleasm-2.6.18-308.24.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130618"/>
          <criterion comment="oracleasm-2.6.18-308.24.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27370" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0346 -- openldap security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0346.html" ref_id="ELSA-2011-0346"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1024" ref_id="CVE-2011-1024"/>
        <description>[2.3.43-12.7]
- fix: CVE-2011-1024 ppolicy forwarded bind failure messages cause success (#680484)

[2.3.43-12.6]
- fix: slapd concurrent access to connections causes slapd to silently die (#677611)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:43.983-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:02.353-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.985-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:06:37.088-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:06:37.088-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:134088"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:134127"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:134010"/>
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:133930"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:133555"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:134085"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:134141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27369" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0133 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0133.html" ref_id="ELSA-2014-0133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1477" ref_id="CVE-2014-1477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1479" ref_id="CVE-2014-1479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1481" ref_id="CVE-2014-1481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1482" ref_id="CVE-2014-1482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1486" ref_id="CVE-2014-1486"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1487" ref_id="CVE-2014-1487"/>
        <description>[24.3.0-2.0.1.el6_5]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Make sure build with nspr-devel >= 4.10.0

[24.3.0-2]
- Update to 24.3.0 ESR Build 2

[24.3.0-1]
- Update to 24.3.0

[24.2.0-2]
- Fixed requested nspr/nss versions</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:26.226-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:02.254-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.868-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:03:56.957-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:03:56.957-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127714"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128069"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27368" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0285 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0285.html" ref_id="ELSA-2014-0285"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4554" ref_id="CVE-2013-4554"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6381" ref_id="CVE-2013-6381"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4483" ref_id="CVE-2013-4483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6885" ref_id="CVE-2013-6885"/>
        <description>kernel
[2.6.18-371.6.1]
- [net] be2net: don't use skb_get_queue_mapping() (Ivan Vecera) [1066302 1063955]
- [ipc] change refcount to atomic_t (Phillip Lougher) [1024866 1024868] {CVE-2013-4483}
- [s390] qeth: buffer overflow in snmp ioctl (Jacob Tanenbaum) [1034402 1034404] {CVE-2013-6381}
- [scsi] AACRAID Driver compat IOCTL missing capability check (Jacob Tanenbaum) [1033531 1033532] {CVE-2013-6383}
- [xen] x86/AMD: work around erratum 793 (Radim Krcmar) [1035834 1035836] {CVE-2013-6885}
- [xen] do not expose hypercalls to rings 1 and 2 of HVM guests (Andrew Jones) [1029112 1029113] {CVE-2013-4554}
- [redhat] kabi: Adding symbol print_hex_dump (Jiri Olsa) [1054055 662558]
- [scsi] Add 'eh_deadline' to limit SCSI EH runtime (Ewan Milne) [1050097 956132]
- [scsi] remove check for 'resetting' (Ewan Milne) [1050097 956132]
- [scsi] dc395: Move 'last_reset' into internal host structure (Ewan Milne) [1050097 956132]
- [scsi] tmscsim: Move 'last_reset' into host structure (Ewan Milne) [1050097 956132]
- [scsi] advansys: Remove 'last_reset' references (Ewan Milne) [1050097 956132]
- [scsi] dpt_i2o: return SCSI_MLQUEUE_HOST_BUSY when in reset (Ewan Milne) [1050097 956132]
- [scsi] dpt_i2o: Remove DPTI_STATE_IOCTL (Ewan Milne) [1050097 956132]
- [net] ipv6: fix leaking uninit port number of offender sockaddr (Florian Westphal) [1035880 1035881] {CVE-2013-7264 CVE-2013-7265 CVE-2013-7281 CVE-2013-7263}
- [net] fix addr_len/msg->msg_namelen assign in recv_error funcs (Florian Westphal) [1035880 1035881] {CVE-2013-7264 CVE-2013-7265 CVE-2013-7281 CVE-2013-7263}
- [net] prevent leakage of uninitialized memory to user in recv (Florian Westphal) [1035880 1035881] {CVE-2013-7264 CVE-2013-7265 CVE-2013-7281 CVE-2013-7263}
- [net] be2net: prevent Tx stall on SH-R when packet size &lt; 32 (Ivan Vecera) [1051535 1007995]
- [net] be2net: Trim padded packets for Lancer (Ivan Vecera) [1051535 1007995]
- [net] be2net: Pad skb to meet min Tx pkt size in lancer (Ivan Vecera) [1051535 1007995]
- [net] be2net: refactor HW workarounds in be_xmit() (Ivan Vecera) [1051535 1007995]
- [fs] exec/ptrace: fix get_dumpable() incorrect tests (Petr Oros) [1039483 1039484] {CVE-2013-2929}

[2.6.18-371.5.1]
- [fs] cifs: stop trying to use virtual circuits (Sachin Prabhu) [1044328 1013469]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:15.368-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:01.882-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.710-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:30:00.600-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:30:00.600-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:127765"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.6.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128132"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.6.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128143"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:127733"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:127993"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:128130"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:128058"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:127464"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:128099"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:127707"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:127588"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:127913"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.6.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128027"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.6.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127509"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.6.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128063"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.6.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127704"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.6.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127934"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.6.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27367" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0769 -- glibc security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0769.html" ref_id="ELSA-2013-0769"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0242" ref_id="CVE-2013-0242"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1914" ref_id="CVE-2013-1914"/>
        <description>[2.5-107.4]
- Add missing patch to avoid use after free (#816647).

[2.5-107.3]
- Fix multibyte character processing crash in regexp (CVE-2013-0242, #951130)
  - Fix getaddrinfo stack overflow resulting in application crash (CVE-2013-1914, #951130)

[2.5-107.2]
- Call feraiseexcept only if exceptions are not masked (#861871).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:56.886-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:01.616-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.623-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:16:59.542-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:16:59.542-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:129673"/>
          <criterion comment="glibc-common is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:129403"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:129694"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:129617"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:129669"/>
          <criterion comment="nscd is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:128772"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27366" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1812 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1812.html" ref_id="ELSA-2013-1812"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5609" ref_id="CVE-2013-5609"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5612" ref_id="CVE-2013-5612"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5613" ref_id="CVE-2013-5613"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5614" ref_id="CVE-2013-5614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5616" ref_id="CVE-2013-5616"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5618" ref_id="CVE-2013-5618"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6671" ref_id="CVE-2013-6671"/>
        <description>[24.2.0-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.2.0-1]
- Update to 24.2.0 ESR

[24.1.0-4]
- Fixed mozbz#938730 - avoid mix of memory allocators (crashes)
  when using system sqlite

[24.1.0-3]
- Fixed locale pickup (rhbz#1034541)

[24.1.0-2]
- Fixed package reinstall issue

[24.1.0-1]
- Update to 24.1.0 ESR

[24.0-0.1]
- Update to 24.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:26.674-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:00.881-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.525-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:29:48.438-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:29:48.438-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128312"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127750"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27364" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0697 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0697.html" ref_id="ELSA-2013-0697"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0800" ref_id="CVE-2013-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0796" ref_id="CVE-2013-0796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0788" ref_id="CVE-2013-0788"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0795" ref_id="CVE-2013-0795"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0793" ref_id="CVE-2013-0793"/>
        <description>[17.0.5-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.5-1]
- Update to 17.0.5 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:36.547-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:00.250-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.210-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:12:20.048-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:12:20.048-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129842"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129733"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27363" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2543 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2543.html" ref_id="ELSA-2013-2543"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" ref_id="CVE-2012-6544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" ref_id="CVE-2013-2206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" ref_id="CVE-2013-2232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" ref_id="CVE-2013-2237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1059" ref_id="CVE-2013-1059"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2851" ref_id="CVE-2013-2851"/>
        <description>[2.6.39-400.109.6]
- block: do not pass disk names as format strings (Kees Cook) [Orabug: 17230083] {CVE-2013-2851}
- libceph: Fix NULL pointer dereference in auth client code (Tyler Hicks) [Orabug: 17230108] {CVE-2013-1059}
- ipv6: ip6_sk_dst_check() must not assume ipv6 dst (Eric Dumazet) [Orabug: 17371078] {CVE-2013-2232}
- af_key: initialize satype in key_notify_policy_flush() (Nicolas Dichtel) [Orabug: 17370788] {CVE-2013-2237}
- Bluetooth: HCI - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17370892] {CVE-2012-6544}
- Bluetooth: L2CAP - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17371050] {CVE-2012-6544}
- Bluetooth: HCI - Fix info leak in getsockopt(HCI_FILTER) (Mathias Krause) [Orabug: 17371065] {CVE-2012-6544}
- sctp: Use correct sideffect command in duplicate cookie handling (Vlad Yasevich) [Orabug: 17371118] {CVE-2013-2206}
- sctp: deal with multiple COOKIE_ECHO chunks (Max Matveev) [Orabug: 17372121] {CVE-2013-2206}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:17.019-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:59.654-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.956-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:129096"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128880"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128675"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:129057"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128990"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128764"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128525"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128826"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128937"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128182"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128942"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:129157"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27361" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0255 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0255.html" ref_id="ELSA-2014-0255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1968" ref_id="CVE-2013-1968"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2112" ref_id="CVE-2013-2112"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0032" ref_id="CVE-2014-0032"/>
        <description>[1.6.11-10]
- add security fixes for CVE-2013-1968, CVE-2013-2112, CVE-2014-0032</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:31.562-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:58.690-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.420-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128053"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128140"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128085"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128114"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128121"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128128"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127818"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:128144"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:128000"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127851"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127854"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:128060"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127397"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127725"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127910"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27360" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0321 -- cvs security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cvs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0321.html" ref_id="ELSA-2012-0321"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0804" ref_id="CVE-2012-0804"/>
        <description>[1.11.23-11.el6_2.1]
- Fix CVE-2012-0804 (Resolves: #784338)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:17.805-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:58.514-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.275-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:27:42.238-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:27:42.238-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cvs is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:132690"/>
            <criterion comment="cvs-inetd is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:132751"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="cvs is earlier than 0:1.11.23-11.el6_2.1" test_ref="oval:org.mitre.oval:tst:132511"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27359" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1452 -- vino security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1452.html" ref_id="ELSA-2013-1452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5745" ref_id="CVE-2013-5745"/>
        <description>[2.28.1-9]
- Reject clients in deferred auth state
  - Bug 1009228</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:23.084-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:58.346-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.177-05:00">ACCEPTED</status_change>
            <modified comment="duplicate" date="2015-02-11T09:24:36.440-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T09:24:36.440-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="vino is earlier than 0:2.13.5-10.el5_10" test_ref="oval:org.mitre.oval:tst:128765"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="vino is earlier than 0:2.28.1-9.el6_4" test_ref="oval:org.mitre.oval:tst:128835"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27358" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2585 -- Unbreakable Enterprise Kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2585.html" ref_id="ELSA-2013-2585"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" ref_id="CVE-2012-6545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" ref_id="CVE-2013-3231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2164" ref_id="CVE-2013-2164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" ref_id="CVE-2013-2234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1928" ref_id="CVE-2013-1928"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2889" ref_id="CVE-2013-2889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2892" ref_id="CVE-2013-2892"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4591" ref_id="CVE-2013-4591"/>
        <description>kernel-uek
[2.6.32-400.33.3uek]
- af_key: fix info leaks in notify messages (Mathias Krause) [Orabug: 17837974] {CVE-2013-2234}
- drivers/cdrom/cdrom.c: use kzalloc() for failing hardware (Jonathan Salwan) [Orabug: 17837971] {CVE-2013-2164}
- fs/compat_ioctl.c: VIDEO_SET_SPU_PALETTE missing error check (Kees Cook) [Orabug: 17837966] {CVE-2013-1928}
- Bluetooth: RFCOMM - Fix info leak in ioctl(RFCOMMGETDEVLIST) (Mathias Krause) [Orabug: 17837959] {CVE-2012-6545}
- Bluetooth: RFCOMM - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17838023] {CVE-2012-6545}
- llc: Fix missing msg_namelen update in llc_ui_recvmsg() (Mathias Krause) [Orabug: 17837945] {CVE-2013-3231}
- HID: pantherlord: validate output report details (Kees Cook) [Orabug: 17837942] {CVE-2013-2892}
- HID: zeroplus: validate output report details (Kees Cook) [Orabug: 17837936] {CVE-2013-2889}
- HID: provide a helper for validating hid reports (Kees Cook) [Orabug: 17837936] 
- NFSv4: Check for buffer length in __nfs4_get_acl_uncached (Sven Wegener) [Orabug: 17837931] {CVE-2013-4591}
- ansi_cprng: Fix off by one error in non-block size request (Neil Horman) [Orabug: 17837999] {CVE-2013-4345}
- HID: validate HID report id size (Kees Cook) [Orabug: 17837925] {CVE-2013-2888}
- ipv6: remove max_addresses check from ipv6_create_tempaddr (Hannes Frederic Sowa) [Orabug: 17837923] {CVE-2013-0343}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:35.000-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:57.868-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.014-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128329 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:59.177-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:17.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127868"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127852"/>
            <criterion comment="ofa-2.6.32-400.33.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128329"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127951"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127730"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:128186"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127834"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127667"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:128421"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128213"/>
            <criterion comment="ofa-2.6.32-400.33.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128330"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128208"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128070"/>
            <criterion comment="ofa-2.6.32-400.33.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128490"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128390"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128195"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128283"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128233"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:127844"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128274"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127856"/>
            <criterion comment="ofa-2.6.32-400.33.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127816"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27357" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0771 -- curl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0771.html" ref_id="ELSA-2013-0771"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1944" ref_id="CVE-2013-1944"/>
        <description>[7.19.7-36]
- fix cookie tailmatching to prevent cross-domain leakage (CVE-2013-1944)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:50.317-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:57.676-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:35.905-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:10:46.807-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:10:46.807-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:129367"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:129254"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:129691"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:129515"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:129742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27353" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0770 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0770.html" ref_id="ELSA-2013-0770"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2420" ref_id="CVE-2013-2420"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2422" ref_id="CVE-2013-2422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2429" ref_id="CVE-2013-2429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2431" ref_id="CVE-2013-2431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1537" ref_id="CVE-2013-1537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2419" ref_id="CVE-2013-2419"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2421" ref_id="CVE-2013-2421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2424" ref_id="CVE-2013-2424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2426" ref_id="CVE-2013-2426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2430" ref_id="CVE-2013-2430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0401" ref_id="CVE-2013-0401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1518" ref_id="CVE-2013-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2383" ref_id="CVE-2013-2383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1488" ref_id="CVE-2013-1488"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1558" ref_id="CVE-2013-1558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1569" ref_id="CVE-2013-1569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2417" ref_id="CVE-2013-2417"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1557" ref_id="CVE-2013-1557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2384" ref_id="CVE-2013-2384"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2415" ref_id="CVE-2013-2415"/>
        <description>[1:1.6.0.0-1.61.1.11.11]
- added and applied (temporally) patch10   fixToFontSecurityFix.patch.
 - fixing regression in fonts introduced by one security patch.
- Resolves: rhbz#950386

[1:1.6.0.0-1.60.1.11.11]
- added and applied (temporally) one more patch to xalan/xerces privileges
 - patch9 jaxp-backport-factoryfinder.patch
- will be upstreamed
- Resolves: rhbz#950386

[1:1.6.0.0-1.59.1.11.11]
- Updated to icedtea6 1.11.11 - fixed xalan/xerxes privledges
- removed patch 8 -  removingOfAarch64.patch.patch - fixed upstream
- Resolves: rhbz#950386

[1:1.6.0.0-1.58.1.11.10]
- Updated to icedtea6 1.11.10
- rewritten java-1.6.0-openjdk-java-access-bridge-security.patch
- excluded aarch64.patch
  - by patch 8 -  removingOfAarch64.patch.patch
- Resolves: rhbz#950386</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:01.422-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:55.635-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.835-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:36:23.617-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:36:23.617-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129580"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128707"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129498"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129574"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129373"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129614"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129683"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129595"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129618"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27350" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1475 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1475.html" ref_id="ELSA-2013-1475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0255" ref_id="CVE-2013-0255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1900" ref_id="CVE-2013-1900"/>
        <description>[8.4.18-1]
- Update to PostgreSQL 8.4.18, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-14.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-15.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-16.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-17.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-18.html
  including fixes for CVE-2013-0255, CVE-2013-1900 (#1017837)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:24.829-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:54.599-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.328-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:38:03.560-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:38:03.560-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128748"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128777"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128557"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128375"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128634"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128217"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128629"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128760"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128798"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128620"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128119"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128316"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128723"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128726"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128528"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128650"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128735"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128785"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128350"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128535"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128684"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27348" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0449 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0449.html" ref_id="ELSA-2014-0449"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1518" ref_id="CVE-2014-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1523" ref_id="CVE-2014-1523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1524" ref_id="CVE-2014-1524"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1529" ref_id="CVE-2014-1529"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1530" ref_id="CVE-2014-1530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1531" ref_id="CVE-2014-1531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1532" ref_id="CVE-2014-1532"/>
        <description>[24.5.0-1.0.1]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.5.0-1]
- Update to 24.5.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:09.770-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:53.788-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.034-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:35:43.573-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:35:43.573-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127628"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127311"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27347" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3016 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3016.html" ref_id="ELSA-2014-3016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101" ref_id="CVE-2014-0101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523" ref_id="CVE-2014-2523"/>
        <description>kernel-uek
[2.6.32-400.34.4uek]
- netfilter: nf_conntrack_dccp: fix skb_header_pointer API usages (Daniel Borkmann)  [Orabug: 18462076]  {CVE-2014-2523}
- net: sctp: fix sctp_sf_do_5_1D_ce to verify if we/peer is AUTH capable (Daniel Borkmann)  [Orabug: 18461091]  {CVE-2014-0101}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:27.083-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:53.308-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:33.811-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127710 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:55.716-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:16.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127541"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126947"/>
            <criterion comment="ofa-2.6.32-400.34.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127802"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127380"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127772"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127484"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127191"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127799"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127728"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127705"/>
            <criterion comment="ofa-2.6.32-400.34.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127786"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127181"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127601"/>
            <criterion comment="ofa-2.6.32-400.34.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127595"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127841"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127795"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127683"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127862"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127798"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127775"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127719"/>
            <criterion comment="ofa-2.6.32-400.34.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27346" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0206 -- openldap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0206.html" ref_id="ELSA-2014-0206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4449" ref_id="CVE-2013-4449"/>
        <description>[2.3.43-27]
- fix: CVE-2013-4449 segfault on certain queries with rwm overlay (#1064145)

[2.3.43-26]
- fix: do not send IPv6 DNS queries when IPv6 is disabled on the host (#812772)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:27.688-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:53.179-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:33.675-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:23:38.687-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:23:38.687-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:128103"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-27.el5_10" test_ref="oval:org.mitre.oval:tst:128037"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:127933"/>
          <criterion comment="openldap-devel is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:127930"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:128084"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:127460"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:127896"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27344" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0536 -- mysql55-mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql55-mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0536.html" ref_id="ELSA-2014-0536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0384" ref_id="CVE-2014-0384"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2419" ref_id="CVE-2014-2419"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2430" ref_id="CVE-2014-2430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2431" ref_id="CVE-2014-2431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2432" ref_id="CVE-2014-2432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2436" ref_id="CVE-2014-2436"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2438" ref_id="CVE-2014-2438"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2440" ref_id="CVE-2014-2440"/>
        <description>[5.5.37-1]
- Update to MySQL 5.5.37, for various fixes described at
  http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html
  Includes fixes for: CVE-2014-2440 CVE-2014-0384 CVE-2014-2432
  CVE-2014-2431 CVE-2014-2430 CVE-2014-2436 CVE-2014-2438 CVE-2014-2419
  Resolves: #1089202</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:44.274-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:52.294-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:33.284-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:50:39.026-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:50:39.026-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql55-mysql is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:127594"/>
          <criterion comment="mysql55-mysql-bench is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:127538"/>
          <criterion comment="mysql55-mysql-devel is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:127638"/>
          <criterion comment="mysql55-mysql-libs is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:126864"/>
          <criterion comment="mysql55-mysql-server is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:126952"/>
          <criterion comment="mysql55-mysql-test is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:126936"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27343" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2589 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2589.html" ref_id="ELSA-2013-2589"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2141" ref_id="CVE-2013-2141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4470" ref_id="CVE-2013-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6367" ref_id="CVE-2013-6367"/>
        <description>kernel-uek
[2.6.32-400.33.4uek]
- kernel/signal.c: stop info leak via the tkill and the tgkill syscalls (Emese Revfy) [Orabug: 17951083] {CVE-2013-2141}
- ip_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951078] {CVE-2013-4470}
- KVM: x86: Fix potential divide by 0 in lapic (CVE-2013-6367) (Andy Honig) [Orabug: 17951073] {CVE-2013-6367}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:51.156-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:51.869-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:33.080-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35092 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:58.339-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:16.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127696"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128230"/>
            <criterion comment="ofa-2.6.32-400.33.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128117"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:128261"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127751"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:128285"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127991"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127825"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127783"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128082"/>
            <criterion comment="ofa-2.6.32-400.33.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128021"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128020"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127695"/>
            <criterion comment="ofa-2.6.32-400.33.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127762"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128214"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:127534"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128202"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128083"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128280"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:127938"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127376"/>
            <criterion comment="ofa-2.6.32-400.33.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128296"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27342" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0907 -- java-1.6.0-openjdk security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0907.html" ref_id="ELSA-2014-0907"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2490" ref_id="CVE-2014-2490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4209" ref_id="CVE-2014-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4216" ref_id="CVE-2014-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4218" ref_id="CVE-2014-4218"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4219" ref_id="CVE-2014-4219"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4244" ref_id="CVE-2014-4244"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4252" ref_id="CVE-2014-4252"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4262" ref_id="CVE-2014-4262"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4263" ref_id="CVE-2014-4263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4266" ref_id="CVE-2014-4266"/>
        <description>[1:1.6.0.1-6.1.13.4]
- moved to  icedteaver 1.13.4
- moved to openjdkver b32 and openjdkdate 15_jul_2014
- added upstreamed patch patch9 rh1115580-unsyncHashMap.patch
- Resolves: rhbz#1115580
- Resolves: rhbz#1115867</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:18.130-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:50.855-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:32.717-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127230 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:45.204-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:32.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127304"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127132"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127303"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127175"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126834"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127377"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127355"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:126673"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127228"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127230"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127321"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127357"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127305"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127152"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127244"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27341" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3048 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3048.html" ref_id="ELSA-2014-3048"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" ref_id="CVE-2014-4943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699" ref_id="CVE-2014-4699"/>
        <description>kernel-uek
[2.6.32-400.36.4uek]
- l2tp: fix an unprivileged user to kernel privilege escalation (Sasha Levin)  [Orabug: 19229529]  {CVE-2014-4943} {CVE-2014-4943}
- ptrace,x86: force IRET path after a ptrace_stop() (Tejun Heo)  [Orabug: 19230692]  {CVE-2014-4699}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:38.270-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:50.601-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:32.513-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:34671 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:57.171-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:16.104-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:126433"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127219"/>
            <criterion comment="ofa-2.6.32-400.36.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126524"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127419"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127263"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127501"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127331"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:126794"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127340"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127160"/>
            <criterion comment="ofa-2.6.32-400.36.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127523"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127119"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126965"/>
            <criterion comment="ofa-2.6.32-400.36.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127260"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127254"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127525"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127512"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:126565"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127072"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127193"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127245"/>
            <criterion comment="ofa-2.6.32-400.36.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126934"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27340" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0129 -- ruby security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0129.html" ref_id="ELSA-2013-0129"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4481" ref_id="CVE-2012-4481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4522" ref_id="CVE-2012-4522"/>
        <description>[1.8.5-27]

- unintentional file creation caused by inserting an illegal NUL character

  * ruby-1.8.6-CVE-2012-4522-io.c-pipe_open-command-name-should-not-contain-null-.patch

  - Related: rhbz#867750



[1.8.5-26]

-  escaping vulnerability about Exception#to_s / NameError#to_s

  * ruby-1.8.7-p371-CVE-2012-4481.patch

  - Resolves: rhbz#867750

- unintentional file creation caused by inserting an illegal NUL character

  * ruby-1.8.6-CVE-2012-4522-io.c-rb_open_file-should-check-NUL-in-path.patch

  - Resolves: rhbz#867750



[1.8.5-25]

- Resolve buffer overflow causing gem installation issues.

  * ruby-1.8.7-syck-avoid-buffer-overflow.patch

  - Resolves: rhbz#834381</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:35.965-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:50.323-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:32.345-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:40:58.379-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:40:58.379-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130356"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130610"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130720"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130071"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130726"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130404"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130334"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130137"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:130260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27336" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0249 -- postgresql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0249.html" ref_id="ELSA-2014-0249"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0060" ref_id="CVE-2014-0060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0061" ref_id="CVE-2014-0061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0062" ref_id="CVE-2014-0062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0063" ref_id="CVE-2014-0063"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0064" ref_id="CVE-2014-0064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0065" ref_id="CVE-2014-0065"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0066" ref_id="CVE-2014-0066"/>
        <description>[8.1.23-10]
- related #1065840: CVE-2014-0062

[8.1.23-9]
- fix #1065840: CVE-2014-0060, CVE-2014-0061, CVE-2014-0063, CVE-2014-0064,
  CVE-2014-0065
- better incorporate strlcpy function (upstream git diff c92f7e..062421)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:25.086-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:48.521-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:31.413-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:30:59.801-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:30:59.801-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:128044"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:127758"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:128018"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:128090"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:127921"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:127880"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:127756"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:127983"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:128141"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:127378"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27335" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0018 -- libxfont security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0018.html" ref_id="ELSA-2014-0018"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6462" ref_id="CVE-2013-6462"/>
        <description>[1.4.5-3]
- cve-2013-6462.patch: sscanf overflow (bug 1049684)
- sscanf-hardening.patch: Some other sscanf hardening fixes (1049684)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:30.896-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:48.318-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:31.217-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:13:30.905-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:13:30.905-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:127927"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:128067"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:128215"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:127999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27334" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-0847-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0847-1.html" ref_id="ELSA-2013-0847-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0153" ref_id="CVE-2013-0153"/>
        <description>kernel
[2.6.18-348.6.1.0.1]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:15.629-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:48.050-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:30.997-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35624 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:57.817-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:15.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129552"/>
          <criterion comment="ocfs2-2.6.18-348.6.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129541"/>
          <criterion comment="oracleasm-2.6.18-348.6.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129518"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129374"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129427"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129110"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128692"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129385"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129388"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129397"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129176"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128970"/>
          <criterion comment="ocfs2-2.6.18-348.6.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129248"/>
          <criterion comment="ocfs2-2.6.18-348.6.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129342"/>
          <criterion comment="ocfs2-2.6.18-348.6.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129559"/>
          <criterion comment="oracleasm-2.6.18-348.6.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129465"/>
          <criterion comment="oracleasm-2.6.18-348.6.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128610"/>
          <criterion comment="oracleasm-2.6.18-348.6.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27329" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0918 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0918.html" ref_id="ELSA-2014-0918"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1547" ref_id="CVE-2014-1547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1555" ref_id="CVE-2014-1555"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1556" ref_id="CVE-2014-1556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1557" ref_id="CVE-2014-1557"/>
        <description>[24.7.0-1.0.1.el6_5]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.7.0-1]
- Update to 24.7.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:09.334-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:44.534-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:29.490-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127343"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126814"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27328" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0274 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0274.html" ref_id="ELSA-2013-0274"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0169" ref_id="CVE-2013-0169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1486" ref_id="CVE-2013-1486"/>
        <description>[ 1:1.6.0.0-1.35.1.11.8.0.1.el5_9]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.35.1.11.8]
- Rebuild with updated source tarball
- Resolves: rhbz#911522

[1:1.6.0.0-1.34.1.11.8]
- Updated to icedtea6 1.11.8
- Removed patch9   7201064.patch
- Removed patch10   8005615.patch
- Removed  not-applied patch 6664509.patch
- Removed mauve as deadly outdated and run on QA
  -  jtreg kept, useless, but valid
- Rewritten java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#911522</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:35.493-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:44.292-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:29.354-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:29:29.264-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:29:29.264-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.35.1.11.8.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130348"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.35.1.11.8.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130411"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.35.1.11.8.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130369"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.35.1.11.8.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130355"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.35.1.11.8.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27327" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0341 -- wireshark security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0341.html" ref_id="ELSA-2014-0341"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5595" ref_id="CVE-2012-5595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5598" ref_id="CVE-2012-5598"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5599" ref_id="CVE-2012-5599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5600" ref_id="CVE-2012-5600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6056" ref_id="CVE-2012-6056"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6060" ref_id="CVE-2012-6060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6061" ref_id="CVE-2012-6061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6062" ref_id="CVE-2012-6062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3557" ref_id="CVE-2013-3557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3559" ref_id="CVE-2013-3559"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4081" ref_id="CVE-2013-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4083" ref_id="CVE-2013-4083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4927" ref_id="CVE-2013-4927"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4931" ref_id="CVE-2013-4931"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4932" ref_id="CVE-2013-4932"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4933" ref_id="CVE-2013-4933"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4934" ref_id="CVE-2013-4934"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4935" ref_id="CVE-2013-4935"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5721" ref_id="CVE-2013-5721"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7112" ref_id="CVE-2013-7112"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2281" ref_id="CVE-2014-2281"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2299" ref_id="CVE-2014-2299"/>
        <description>[1.0.15-6.0.1.el5]
- Added oracle-ocfs2-network.patch
- increase max packet size to 65536 (Herbert van den Bergh) [orabug 13542633]

[1.0.15-6]
- security patches
- Resolves: CVE-2012-6056
            CVE-2012-6060
            CVE-2012-6061
            CVE-2012-6062
            CVE-2013-3557
            CVE-2013-3559
            CVE-2013-4081
            CVE-2013-4083
            CVE-2013-4927
            CVE-2013-4931
            CVE-2013-4932
            CVE-2013-4933
            CVE-2013-4934
            CVE-2013-4935
            CVE-2013-5721
            CVE-2013-7112
            CVE-2014-2281
            CVE-2014-2299</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:10.777-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:42.475-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:29.176-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:20:55.969-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:20:55.969-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="wireshark is earlier than 0:1.0.15-6.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126900"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-6.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127221"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27326" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0741 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0741.html" ref_id="ELSA-2014-0741"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1533" ref_id="CVE-2014-1533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1538" ref_id="CVE-2014-1538"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1541" ref_id="CVE-2014-1541"/>
        <description>[24.6.0-1.0.1.el6_5]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[24.6.0-1]
- Update to 24.6.0 ESR

[24.5.0-2]
- Disabled unused patches</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:15.356-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:42.175-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:29.091-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:46:51.933-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:46:51.933-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127366"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27325" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1791 -- nss and nspr security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1791.html" ref_id="ELSA-2013-1791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1739" ref_id="CVE-2013-1739"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1741" ref_id="CVE-2013-1741"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5605" ref_id="CVE-2013-5605"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5606" ref_id="CVE-2013-5606"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5607" ref_id="CVE-2013-5607"/>
        <description>nspr
[4.10.2-2]
- Fix changelog comments
- Resolves: rhbz#1032466 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [rhel-5.10]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:43.612-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:41.713-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:28.966-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:26:43.418-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:26:43.418-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.10.2-2.el5_10" test_ref="oval:org.mitre.oval:tst:127882"/>
          <criterion comment="nss is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:128297"/>
          <criterion comment="nspr-devel is earlier than 0:4.10.2-2.el5_10" test_ref="oval:org.mitre.oval:tst:128354"/>
          <criterion comment="nss-devel is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:127726"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:128436"/>
          <criterion comment="nss-tools is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:128399"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27324" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1090 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1090.html" ref_id="ELSA-2013-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4073" ref_id="CVE-2013-4073"/>
        <description>[1.8.7.352-12]
- Fix regression introduced by CVE-2013-4073
  https://bugs.ruby-lang.org/issues/8575
  * ruby-2.0.0-p255-Fix-SSL-client-connection-crash-for-SAN-marked-critical.patch
  - Related: rhbz#979300

[1.8.7.352-11]
- hostname check bypassing vulnerability in SSL client.
  * ruby-1.8.7-p374-CVE-2013-4073-fix-hostname-verification.patch
  - Resolves: rhbz#979300</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:32.370-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:41.484-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:28.822-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:55:54.506-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:55:54.506-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129100"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:128814"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129008"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:128508"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129228"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:128710"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129031"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129270"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129191"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129149"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129189"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129251"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129175"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129205"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129091"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129226"/>
            <criterion comment="ruby-static is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129128"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:128591"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27323" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0740-1 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0740-1.html" ref_id="ELSA-2014-0740-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7339" ref_id="CVE-2013-7339"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <description>kernel
[2.6.18-371.9.1.0.1]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:34.446-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:41.232-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:28.682-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127550 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:56.894-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:15.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127503"/>
          <criterion comment="ocfs2-2.6.18-371.9.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127609"/>
          <criterion comment="oracleasm-2.6.18-371.9.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127504"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127516"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127573"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127603"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127345"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127386"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127212"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127527"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127570"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.9.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127013"/>
          <criterion comment="ocfs2-2.6.18-371.9.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127602"/>
          <criterion comment="ocfs2-2.6.18-371.9.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127590"/>
          <criterion comment="ocfs2-2.6.18-371.9.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127550"/>
          <criterion comment="oracleasm-2.6.18-371.9.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127531"/>
          <criterion comment="oracleasm-2.6.18-371.9.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:126953"/>
          <criterion comment="oracleasm-2.6.18-371.9.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27322" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0211 -- postgresql84 and postgresql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0211.html" ref_id="ELSA-2014-0211"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0060" ref_id="CVE-2014-0060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0061" ref_id="CVE-2014-0061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0062" ref_id="CVE-2014-0062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0063" ref_id="CVE-2014-0063"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0064" ref_id="CVE-2014-0064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0065" ref_id="CVE-2014-0065"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0066" ref_id="CVE-2014-0066"/>
        <description>[8.4.20-1]
- Update to PostgreSQL 8.4.20 (#1065843) for fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-20.html</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:14.451-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:40.530-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:28.242-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:19:53.793-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:19:53.793-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127860"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127909"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127998"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127827"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127156"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127426"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127779"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:128087"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:128007"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:128124"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127864"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127988"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127916"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:128015"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:128123"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127453"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:128047"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127952"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127680"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127840"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127723"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127866"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27320" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0323 -- httpd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0323.html" ref_id="ELSA-2012-0323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3607" ref_id="CVE-2011-3607"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3639" ref_id="CVE-2011-3639"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0031" ref_id="CVE-2012-0031"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0053" ref_id="CVE-2012-0053"/>
        <description>[2.2.3-63.0.1.el5_8.1]
- Fix mod_ssl always performing full renegotiation (orabug 12423387)
- replace index.html with Oracle's index page oracle_index.html
- update vstring and distro in specfile

[2.2.3-63.1]
- add security fixes for CVE-2012-0053, CVE-2012-0031, CVE-2011-3607 (#787596)	
- remove patch for CVE-2011-3638, obviated by fix for CVE-2011-3639</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:03.196-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:39.494-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.855-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:43:10.685-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:43:10.685-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd is earlier than 0:2.2.3-63.0.1.el5_8.1" test_ref="oval:org.mitre.oval:tst:132273"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-63.0.1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131851"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.3-63.0.1.el5_8.1" test_ref="oval:org.mitre.oval:tst:132560"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-63.0.1.el5_8.1" test_ref="oval:org.mitre.oval:tst:132600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27319" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3009 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3009.html" ref_id="ELSA-2014-3009"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7265" ref_id="CVE-2013-7265"/>
        <description>[2.6.39-400.214.3]
- inet: fix addr_len/msg->msg_namelen assignment in recv_error and rxpmtu functions (Hannes Frederic Sowa)  [18247289]  {CVE-2013-7263} {CVE-2013-7265}

[2.6.39-400.214.2]
- inet: prevent leakage of uninitialized memory to user in recv syscalls (Hannes Frederic Sowa)  [18238382]  {CVE-2013-7263} {CVE-2013-7265}
- exec/ptrace: fix get_dumpable() incorrect tests (Kees Cook)  [18238353]  {CVE-2013-2929}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:28.577-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:39.355-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.719-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:128112"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127403"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127497"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127777"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:128120"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127746"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127774"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:128108"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127697"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127932"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127592"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127473"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27315" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0391 -- libvirt security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0391.html" ref_id="ELSA-2011-0391"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1146" ref_id="CVE-2011-1146"/>
        <description>[0.8.1-27.0.1.el6_0.5]
- Replace docs/et.png in tarball with blank image

[0.8.1-27.el6_0.5]
- Properly report error in virConnectDomainXMLToNative (CVE-2011-1146)

[0.8.1-27.el6_0.4]
- Add missing checks for read-only connections (CVE-2011-1146)

[0.8.1-27.el6_0.3]
- Remove patches not suitable for proper Z-stream:
    - Export host information through SMBIOS to guests (rhbz#652678)
    - Support forcing a CDROM eject (rhbz#658147)
- Plug several memory leaks (rhbz#672549)
- Avoid memory overhead of matchpathcon (rhbz#672554)
- Do not start libvirt-guests if that service is off (rhbz#668694)

[0.8.1-27.el6_0.2]
- spec file cleanups (rhbz#662045)
- Fix deadlock on concurrent multiple bidirectional migration (rhbz#662043)
- Fix off-by-one error in clock-variable (rhbz#662046)
- Export host information through SMBIOS to guests (rhbz#652678)
- Ensure device is deleted from guest after unplug (rhbz#662041)
- Distinguish between QEMU domain shutdown and crash (rhbz#662042)

[0.8.1-27.el6_0.1]
- Fix JSON migrate_set_downtime command (rhbz#658143)
- Make SASL work over UNIX domain sockets (rhbz#658144)
- Let qemu group look below /var/lib/libvirt/qemu/ (rhbz#656972)
- Fix save/restore on root_squashed NFS (rhbz#656355)
- Fix race on multiple migration (rhbz#658141)
- Export host information through SMBIOS to guests (rhbz#652678)
- Support forcing a CDROM eject (rhbz#658147)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:09.874-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:38.515-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.092-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:46:13.114-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:46:13.114-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvirt is earlier than 0:0.8.2-15.0.1.el5_6.3" test_ref="oval:org.mitre.oval:tst:133946"/>
            <criterion comment="libvirt-devel is earlier than 0:0.8.2-15.0.1.el5_6.3" test_ref="oval:org.mitre.oval:tst:134187"/>
            <criterion comment="libvirt-python is earlier than 0:0.8.2-15.0.1.el5_6.3" test_ref="oval:org.mitre.oval:tst:134162"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvirt is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134189"/>
            <criterion comment="libvirt-client is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133953"/>
            <criterion comment="libvirt-devel is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133544"/>
            <criterion comment="libvirt-python is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27314" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0640 -- tomcat5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0640.html" ref_id="ELSA-2013-0640"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5887" ref_id="CVE-2012-5887"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5886" ref_id="CVE-2012-5886"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5885" ref_id="CVE-2012-5885"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3546" ref_id="CVE-2012-3546"/>
        <description>[0:5.5.23-0jpp.38]
- Resolves: CVE-2012-3439 rhbz#882008 three DIGEST authentication
- implementation
- Resolves: CVE-2012-3546, rhbz#913034 Bypass of security constraints.
- Remove unneeded handling of FORM authentication in RealmBase</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:59.719-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:38.052-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:26.843-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:17:57.979-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:17:57.979-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129942"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129971"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129424"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129921"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129613"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129849"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129499"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129701"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129620"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:130030"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:129881"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27313" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0474 -- tomcat5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0474.html" ref_id="ELSA-2012-0474"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4858" ref_id="CVE-2011-4858"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022" ref_id="CVE-2012-0022"/>
        <description>[0:5.5.23-0jpp.31]
- Resolves: CVE-2012 regression. Changed patch file.

[0:5.5.23-0jpp.30]
- Resolves: CVE-2012-0022, CVE-2011-4858

[0:5.5.23-0jpp.27]
- Resolves CVE-2011-0013 rhbz 675933
- Resolves CVE-2011-3718 rhbz 675933

[0:5.5.23-0jpp.23]
- Resolves CVE-2011-1184 rhbz 744984
- Resolves CVE-2011-2204 rhbz 719188</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:15.915-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:37.775-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:26.640-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:24:15.166-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:24:15.166-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132027"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132494"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132371"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132459"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132344"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132000"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132532"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132068"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132504"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132458"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:132554"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27311" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0125 -- wireshark security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0125.html" ref_id="ELSA-2013-0125"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1958" ref_id="CVE-2011-1958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1959" ref_id="CVE-2011-1959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2175" ref_id="CVE-2011-2175"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2698" ref_id="CVE-2011-2698"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4102" ref_id="CVE-2011-4102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0041" ref_id="CVE-2012-0041"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0042" ref_id="CVE-2012-0042"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0066" ref_id="CVE-2012-0066"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0067" ref_id="CVE-2012-0067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4285" ref_id="CVE-2012-4285"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4289" ref_id="CVE-2012-4289"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4290" ref_id="CVE-2012-4290"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4291" ref_id="CVE-2012-4291"/>
        <description>[1.0.15-5.0.1.el5]

- Added oracle-ocfs2-network.patch

- increase max packet size to 65536 (Herbert van den Bergh) [orabug 13542633]



[1.0.15-5]

- fixed CVE-2012-4285, CVE-2012-4289, CVE-2012-4291 and CVE-2012-4290

  (#849521)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:31.483-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:36.722-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:26.183-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:36:36.817-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:36:36.817-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="wireshark is earlier than 0:1.0.15-5.0.1.el5" test_ref="oval:org.mitre.oval:tst:130665"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-5.0.1.el5" test_ref="oval:org.mitre.oval:tst:130112"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27307" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0266 -- sudo security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0266.html" ref_id="ELSA-2014-0266"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0106" ref_id="CVE-2014-0106"/>
        <description>[1.7.2p1-29]
- added patch for CVE-2014-0106: certain environment variables not
  sanitized when env_reset is disabled
  Resolves: rhbz#1072210</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:18.608-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:34.953-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:25.334-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:26:05.964-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:26:05.964-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-29.el5_10" test_ref="oval:org.mitre.oval:tst:127853"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27304" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2546 -- Unbreakable Enterprise Kernel security and bug fix  update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2546.html" ref_id="ELSA-2013-2546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2164" ref_id="CVE-2013-2164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" ref_id="CVE-2013-2234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6549" ref_id="CVE-2012-6549"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1772" ref_id="CVE-2013-1772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2140" ref_id="CVE-2013-2140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3076" ref_id="CVE-2013-3076"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4163" ref_id="CVE-2013-4163"/>
        <description>[2.6.39-400.209.1]

- Revert 'stop mig handler when lockres in progress ,and return -EAGAIN' (Srinivas Eeda) [Orabug: 16924802] 

- ocfs2/dlm: Fix list traversal in dlm_process_recovery_data (Srinivas Eeda) [Orabug: 17432400] 

- ocfs2/dlm: ocfs2 dlm umount skip migrating lockres (Srinivas Eeda) [Orabug: 16859627]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:18.125-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:33.839-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:24.719-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128774"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128883"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128743"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:129033"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128813"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128909"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:129117"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:129120"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:128851"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:128916"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:128545"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:129034"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27303" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0621 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0621.html" ref_id="ELSA-2013-0621"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" ref_id="CVE-2013-0268"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" ref_id="CVE-2013-0871"/>
        <description>kernel
[2.6.18-348.3.1]
- [utrace] ensure arch_ptrace() can never race with SIGKILL (Oleg Nesterov) [912071 912072] {CVE-2013-0871}
- [x86] msr: Add capabilities check (Nikola Pajkovsky) [908696 908697] {CVE-2013-0268}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:49.950-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:33.536-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:24.429-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:10:18.173-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:10:18.173-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:130118"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.3.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129680"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.3.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129994"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:129790"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:129707"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:130097"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:130019"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:130088"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:130156"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:129884"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:129933"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:129949"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.3.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129972"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.3.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130076"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-348.3.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130144"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.3.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130083"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.3.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130043"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-348.3.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129959"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27299" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0737 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0737.html" ref_id="ELSA-2013-0737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1849" ref_id="CVE-2013-1849"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1845" ref_id="CVE-2013-1845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1847" ref_id="CVE-2013-1847"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1846" ref_id="CVE-2013-1846"/>
        <description>[1.6.11-9]
- add security fixes for CVE-2013-1846, CVE-2013-1847, CVE-2013-1849 (#947372)

[1.6.11-8]
- add security fix for CVE-2013-1845 (#947372)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:54.682-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:31.684-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:23.397-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:46:29.702-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:46:29.702-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129803"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129797"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:128871"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129734"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129411"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129589"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129640"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129759"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129804"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129539"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129629"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:128824"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129750"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129784"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129681"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27298" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3068 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3068.html" ref_id="ELSA-2014-3068"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4667" ref_id="CVE-2014-4667"/>
        <description>[2.6.39-400.215.7]
- sctp: Fix sk_ack_backlog wrap-around problem (Xufeng Zhang)  [Orabug: 19404245]  {CVE-2014-4667}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:20.989-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:31.468-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:23.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126861"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126994"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126826"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126780"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126217"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:127007"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126561"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126979"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:127025"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126427"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126820"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126288"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27296" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0433-1 -- kernel security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0433-1.html" ref_id="ELSA-2014-0433-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6638" ref_id="CVE-2012-6638"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <description>kernel
[2.6.18-371.8.1.0.1]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:25.816-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:30.850-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:22.905-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35311 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:58.594-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:14.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127626"/>
          <criterion comment="ocfs2-2.6.18-371.8.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127649"/>
          <criterion comment="oracleasm-2.6.18-371.8.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127744"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127493"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127511"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127690"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127558"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127382"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127569"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127320"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127557"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.8.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:126759"/>
          <criterion comment="ocfs2-2.6.18-371.8.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127755"/>
          <criterion comment="ocfs2-2.6.18-371.8.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127701"/>
          <criterion comment="ocfs2-2.6.18-371.8.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127562"/>
          <criterion comment="oracleasm-2.6.18-371.8.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127754"/>
          <criterion comment="oracleasm-2.6.18-371.8.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127627"/>
          <criterion comment="oracleasm-2.6.18-371.8.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127555"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27295" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0164 -- openssl097a security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl097a</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0164.html" ref_id="ELSA-2010-0164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" ref_id="CVE-2009-3555"/>
        <description>[0.9.7a-9.2]
- CVE-2009-3555 - support the secure renegotiation RFC (#533125)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:56.321-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:30.697-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:22.775-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:05:14.638-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:05:14.638-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="openssl097a is earlier than 0:0.9.7a-9.el5_4.2" test_ref="oval:org.mitre.oval:tst:135257"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27292" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0983 -- curl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0983.html" ref_id="ELSA-2013-0983"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2174" ref_id="CVE-2013-2174"/>
        <description>[7.19.7-37]
- fix heap-based buffer overflow in curl_easy_unescape() (CVE-2013-2174)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:19.267-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:29.749-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:22.263-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:03:31.018-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:03:31.018-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:129420"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:129395"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:129426"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:128712"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:128683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27290" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2025 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2025.html" ref_id="ELSA-2012-2025"/>
        <description>[2.6.39-200.29.2]

- epoll: clear the tfile_check_list on -ELOOP (Joe Jin) {CVE-2012-3375}

- Don't limit non-nested epoll paths (Jason Baron)

- epoll: kabi fixups for epoll limit wakeup paths (Joe Jin) {CVE-2011-1083}

- epoll: limit paths (Jason Baron)  {CVE-2011-1083}

- cred: copy_process() should clear child->replacement_session_keyring (Oleg

  Nesterov)  {CVE-2012-2745}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:09.723-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:26.406-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:21.062-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131646"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131614"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131645"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131257"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131394"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131533"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131435"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131538"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131636"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:130896"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131564"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131633"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27286" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0132 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0132.html" ref_id="ELSA-2014-0132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1477" ref_id="CVE-2014-1477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1479" ref_id="CVE-2014-1479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1481" ref_id="CVE-2014-1481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1482" ref_id="CVE-2014-1482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1486" ref_id="CVE-2014-1486"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1487" ref_id="CVE-2014-1487"/>
        <description>[24.3.0-2.0.1.el6_5]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.3.0-2]
- Update to 24.3.0 ESR Build 2

[24.3.0-1]
- Update to 24.3.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:41.473-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:24.846-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:20.238-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:43:06.824-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:43:06.824-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128097"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27285" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0310 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0310.html" ref_id="ELSA-2014-0310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1493" ref_id="CVE-2014-1493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1497" ref_id="CVE-2014-1497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1505" ref_id="CVE-2014-1505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1508" ref_id="CVE-2014-1508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1509" ref_id="CVE-2014-1509"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1510" ref_id="CVE-2014-1510"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1511" ref_id="CVE-2014-1511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1512" ref_id="CVE-2014-1512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1513" ref_id="CVE-2014-1513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1514" ref_id="CVE-2014-1514"/>
        <description>[24.4.0-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.4.0-1]
- Update to 24.4.0 ESR

[24.3.0-4]
- Fixed rhbz#1070467 - Enable Add Ons by default in Firefox

[24.3.0-3]
- Fixed rhbz#1054832 - Firefox does not support Camellia cipher</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:11.981-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:23.732-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:19.884-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:20:25.022-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:20:25.022-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128031"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127672"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27283" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1264 -- postgresql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1264.html" ref_id="ELSA-2012-1264"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3488" ref_id="CVE-2012-3488"/>
        <description>[8.1.23-6]
- Back-port upstream fix for CVE-2012-3488
Resolves: #852015</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:22.577-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:22.031-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:19.121-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:17:47.796-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:17:47.796-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131073"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131204"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131143"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:130581"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131263"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131076"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131127"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131221"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:131266"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:130970"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27281" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-1348-1 -- Oracle Linux 5 kernel update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1348-1.html" ref_id="ELSA-2013-1348-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4398" ref_id="CVE-2012-4398"/>
        <description>kernel
[2.6.18-371.0.0.0.1]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:53.912-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:21.433-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:18.840-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35504 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:01.154-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:13.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128908"/>
          <criterion comment="ocfs2-2.6.18-371.0.0.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129106"/>
          <criterion comment="oracleasm-2.6.18-371.0.0.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129090"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128997"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128836"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:129020"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128366"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128394"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128960"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128973"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128936"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.0.0.0.1.el5" test_ref="oval:org.mitre.oval:tst:128932"/>
          <criterion comment="ocfs2-2.6.18-371.0.0.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128628"/>
          <criterion comment="ocfs2-2.6.18-371.0.0.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128685"/>
          <criterion comment="ocfs2-2.6.18-371.0.0.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128930"/>
          <criterion comment="oracleasm-2.6.18-371.0.0.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128595"/>
          <criterion comment="oracleasm-2.6.18-371.0.0.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128843"/>
          <criterion comment="oracleasm-2.6.18-371.0.0.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128367"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27280" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1326 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1326.html" ref_id="ELSA-2014-1326"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2497" ref_id="CVE-2014-2497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3587" ref_id="CVE-2014-3587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3597" ref_id="CVE-2014-3597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4670" ref_id="CVE-2014-4670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4698" ref_id="CVE-2014-4698"/>
        <description>[5.3.3-27.2]
        - spl: fix use-after-free in ArrayIterator due to object
          change during sorting. CVE-2014-4698
        - spl: fix use-after-free in SPL Iterators. CVE-2014-4670
        - gd: fix NULL pointer dereference in gdImageCreateFromXpm.
          CVE-2014-2497
        - fileinfo: fix incomplete fix for CVE-2012-1571 in
          cdf_read_property_info. CVE-2014-3587
        - core: fix incomplete fix for CVE-2014-4049 DNS TXT
          record parsing. CVE-2014-3597</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:02.175-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:20.554-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:18.405-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126797"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126454"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126850"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126514"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126592"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126773"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126489"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126874"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126563"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126286"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126903"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126883"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125998"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126742"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126219"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126963"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126300"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126964"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126155"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126923"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126661"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126409"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126833"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126474"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126828"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126153"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126909"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126548"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126971"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126802"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126226"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126737"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126375"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126896"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126830"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126641"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126924"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126957"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126695"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126522"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126922"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126935"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126728"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126796"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126713"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126723"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126611"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27279" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1806 -- samba and samba3x security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1806.html" ref_id="ELSA-2013-1806"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408" ref_id="CVE-2013-4408"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475" ref_id="CVE-2013-4475"/>
        <description>[3.6.9-167]
- resolves: #1018037 - Fix CVE-2013-4408.

[3.6.9-165]
- resolves: #1028086 - Fix CVE-2013-4475.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:33.710-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:20.143-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:18.187-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:56:57.005-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:56:57.005-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128360"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128127"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:127817"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128406"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:127839"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128298"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:127434"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128432"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:127879"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:127665"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128038"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:127451"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128348"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128306"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128201"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128411"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128220"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128051"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128342"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128446"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27276" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0400 -- tetex security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tetex</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0400.html" ref_id="ELSA-2010-0400"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0739" ref_id="CVE-2010-0739"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0829" ref_id="CVE-2010-0829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166" ref_id="CVE-2009-0166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195" ref_id="CVE-2009-0195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0791" ref_id="CVE-2009-0791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799" ref_id="CVE-2009-0799"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800" ref_id="CVE-2009-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179" ref_id="CVE-2009-1179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180" ref_id="CVE-2009-1180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181" ref_id="CVE-2009-1181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182" ref_id="CVE-2009-1182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183" ref_id="CVE-2009-1183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608" ref_id="CVE-2009-3608"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609" ref_id="CVE-2009-3609"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1440" ref_id="CVE-2010-1440"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146" ref_id="CVE-2009-0146"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147" ref_id="CVE-2009-0147"/>
        <description>[3.0-33.8.el5.5]
- unify patches for CVE-2010-0739 and CVE-2010-1440

[3.0-33.8.el5.4]
- fix CVE-2010-1440 (#586819)

[3.0-33.8.el5.3]
- initialize data in arithmetic coder elsewhere (CVE-2009-0146)

[3.0-33.8.el5.2]
- initialize dataLen to properly fix CVE-2009-0146

[3.0-33.8.el5.1]
- fix CVE-2010-0739 CVE-2010-0829 CVE-2007-5936 CVE-2007-5937
CVE-2009-0146 CVE-2009-0195 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799
CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182
CVE-2009-1183 CVE-2009-0791 CVE-2009-3608 CVE-2009-3609
Resolves: #577328</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:06:12.820-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:17.306-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:17.171-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:32:18.887-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:32:18.887-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:135087"/>
          <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:134887"/>
          <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:135172"/>
          <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:135160"/>
          <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:135062"/>
          <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:135174"/>
          <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:135080"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27275" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0285-1 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0285-1.html" ref_id="ELSA-2014-0285-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4554" ref_id="CVE-2013-4554"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6381" ref_id="CVE-2013-6381"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4483" ref_id="CVE-2013-4483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6885" ref_id="CVE-2013-6885"/>
        <description>kernel
[2.6.18-371.6.1.0.1]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:17.776-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:16.337-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:16.873-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35336 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:02.572-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:13.423-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128014"/>
          <criterion comment="ocfs2-2.6.18-371.6.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127920"/>
          <criterion comment="oracleasm-2.6.18-371.6.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127693"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127883"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127815"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127650"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127480"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127147"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128026"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128043"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127791"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.6.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127919"/>
          <criterion comment="ocfs2-2.6.18-371.6.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128146"/>
          <criterion comment="ocfs2-2.6.18-371.6.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127831"/>
          <criterion comment="ocfs2-2.6.18-371.6.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127514"/>
          <criterion comment="oracleasm-2.6.18-371.6.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127923"/>
          <criterion comment="oracleasm-2.6.18-371.6.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128133"/>
          <criterion comment="oracleasm-2.6.18-371.6.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127904"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27274" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0916 -- nss and nspr security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0916.html" ref_id="ELSA-2014-0916"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1544" ref_id="CVE-2014-1544"/>
        <description>nspr
[4.10.2-4]
- Rebase to nspr-4.10.6
- Resolves: Bug 1116199

[4.10.2-3]
- Retagging
- Resolves: rhbz#1032466

nss
[3.15.3-7]
- Remove an unused patch
- Related: Bug 1116199

[3.15.3-6]
- Fix race-condition in certificate validation
- Resolves: Bug 1116199

[3.15.3-5]
- Remove two unused patches
- Resolves: Bug 1042683 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:13.049-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:16.074-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:16.763-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.10.6-1.el5_10" test_ref="oval:org.mitre.oval:tst:127246"/>
          <criterion comment="nss is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:127266"/>
          <criterion comment="nspr-devel is earlier than 0:4.10.6-1.el5_10" test_ref="oval:org.mitre.oval:tst:127277"/>
          <criterion comment="nss-devel is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:126925"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:127249"/>
          <criterion comment="nss-tools is earlier than 0:3.15.3-7.el5_10" test_ref="oval:org.mitre.oval:tst:127347"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27270" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0919 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0919.html" ref_id="ELSA-2014-0919"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1547" ref_id="CVE-2014-1547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1555" ref_id="CVE-2014-1555"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1556" ref_id="CVE-2014-1556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1557" ref_id="CVE-2014-1557"/>
        <description>[24.7.0-1.0.1.el6_5]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[24.7.0-1]
- Update to 24.7.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:10.760-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:14.608-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:16.126-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126961"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27265" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0223 -- libtiff security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0223.html" ref_id="ELSA-2014-0223"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1960" ref_id="CVE-2013-1960"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1961" ref_id="CVE-2013-1961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4231" ref_id="CVE-2013-4231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4232" ref_id="CVE-2013-4232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4243" ref_id="CVE-2013-4243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4244" ref_id="CVE-2013-4244"/>
        <description>[3.8.2-19]
- Resolves: #1063460 CVE-2013-1960 CVE-2013-1961 CVE-2013-4231 CVE-2013-4232 CVE-2013-4243 CVE-2013-4244
  libtiff various flaws</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:40.580-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:12.145-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:15.108-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:28:33.509-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:28:33.509-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtiff is earlier than 0:3.8.2-19.el5_10" test_ref="oval:org.mitre.oval:tst:128118"/>
          <criterion comment="libtiff-devel is earlier than 0:3.8.2-19.el5_10" test_ref="oval:org.mitre.oval:tst:127759"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27262" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1671 -- rsyslog5 and rsyslog security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rsyslog</product>
          <product>rsyslog5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1671.html" ref_id="ELSA-2014-1671"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3634" ref_id="CVE-2014-3634"/>
        <description>[5.8.12-5.0.1]
        - use setsid() to get a controlling session and process group [Orabug: 17364545]
        [5.8.12-5]
        - fix CVE-2014-3634
          resolves: #1149158</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:23.766-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:09.573-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:14.116-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog5 is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126613"/>
            <criterion comment="rsyslog5-gnutls is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126495"/>
            <criterion comment="rsyslog5-gssapi is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126582"/>
            <criterion comment="rsyslog5-mysql is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:125811"/>
            <criterion comment="rsyslog5-pgsql is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126734"/>
            <criterion comment="rsyslog5-snmp is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126646"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126557"/>
            <criterion comment="rsyslog-gnutls is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126682"/>
            <criterion comment="rsyslog-gssapi is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126771"/>
            <criterion comment="rsyslog-mysql is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126415"/>
            <criterion comment="rsyslog-pgsql is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126787"/>
            <criterion comment="rsyslog-relp is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126736"/>
            <criterion comment="rsyslog-snmp is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126601"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27257" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0603 -- gnupg2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnupg2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0603.html" ref_id="ELSA-2010-0603"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2547" ref_id="CVE-2010-2547"/>
        <description>[2.0.10-3.1]
- fix use after free when importing certain X509 certificates
  CVE-2010-2547 (#618156)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:05:52.595-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:05.211-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:12.285-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:45:20.347-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:45:20.347-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="gnupg2 is earlier than 0:2.0.10-3.el5_5.1" test_ref="oval:org.mitre.oval:tst:134074"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27256" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1140 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1140.html" ref_id="ELSA-2013-1140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1701" ref_id="CVE-2013-1701"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1709" ref_id="CVE-2013-1709"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1710" ref_id="CVE-2013-1710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1713" ref_id="CVE-2013-1713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1714" ref_id="CVE-2013-1714"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1717" ref_id="CVE-2013-1717"/>
        <description>firefox
[17.0.8-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.8-1]
- Update to 17.0.8 ESR

xulrunner
[17.0.8-3.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.8-3]
- Update to 17.0.8 ESR Build 2

[17.0.8-2]
- Added fix for rhbz#990921 - firefox does not build with
  required nss/nspr

[17.0.8-1]
- Update to 17.0.8 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:11.811-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:04.572-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:11.984-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:28:15.023-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:28:15.023-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129146"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129180"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128874"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128812"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128986"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129283"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27255" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-1348 -- Oracle linux 5 kernel update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1348.html" ref_id="ELSA-2013-1348"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4398" ref_id="CVE-2012-4398"/>
        <description>kernel

[2.6.18-371]

- [net] be2net: enable polling prior enabling interrupts globally (Ivan Vecera) [987539]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:07.439-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:04.270-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:11.820-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128991 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:55.943-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:12.579-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:128852"/>
          <criterion comment="ocfs2-2.6.18-371.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128594"/>
          <criterion comment="oracleasm-2.6.18-371.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128891"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:128885"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:128111"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:129068"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:129072"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:129083"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:128844"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:129024"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:128992"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.el5" test_ref="oval:org.mitre.oval:tst:128842"/>
          <criterion comment="ocfs2-2.6.18-371.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128991"/>
          <criterion comment="ocfs2-2.6.18-371.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129082"/>
          <criterion comment="ocfs2-2.6.18-371.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128865"/>
          <criterion comment="oracleasm-2.6.18-371.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129013"/>
          <criterion comment="oracleasm-2.6.18-371.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128747"/>
          <criterion comment="oracleasm-2.6.18-371.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27254" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2034 -- Unbreakable Enterprise kernel Security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2034.html" ref_id="ELSA-2012-2034"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313" ref_id="CVE-2012-2313"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2390" ref_id="CVE-2012-2390"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3430" ref_id="CVE-2012-3430"/>
        <description>[2.6.39-200.32.1]
- dl2k: Clean up rio_ioctl (Stephan Mueller) [Orabug: 14680245] {CVE-2012-2313}
- hugetlb: fix resv_map leak in error path (Christoph Lameter) [Orabug: 14680284] {CVE-2012-2390}
- rds: set correct msg_namelen (Jay Fenlason) [Orabug: 14680018] {CVE-2012-3430}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:37.440-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:03.676-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:11.648-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130949"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:131168"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130792"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130946"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130823"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130996"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131187"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131195"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:130230"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131037"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131152"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:130794"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27250" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3043 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3043.html" ref_id="ELSA-2014-3043"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6378" ref_id="CVE-2013-6378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1874" ref_id="CVE-2014-1874"/>
        <description>kernel-uek
[2.6.32-400.36.3uek]
- fix autofs/afs/etc. magic mountpoint breakage (Al Viro)  [Orabug: 19028505]  {CVE-2014-0203}
- SELinux:  Fix kernel BUG on empty security contexts. (Stephen Smalley)  [Orabug: 19028381]  {CVE-2014-1874}
- floppy: don't write kernel-only members to FDRAWCMD ioctl output (Matthew Daley)  [Orabug: 19028446]  {CVE-2014-1738}
- floppy: ignore kernel-only members in FDRAWCMD ioctl input (Matthew Daley)  [Orabug: 19028439]  {CVE-2014-1737}
- libertas: potential oops in debugfs (Dan Carpenter)  [Orabug: 19028417]  {CVE-2013-6378}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:10.261-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:02.291-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:10.971-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35309 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:59.411-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:12.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:126800"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127213"/>
            <criterion comment="ofa-2.6.32-400.36.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127465"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127385"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127540"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127615"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127163"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127436"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127388"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127216"/>
            <criterion comment="ofa-2.6.32-400.36.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127587"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127566"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127596"/>
            <criterion comment="ofa-2.6.32-400.36.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127581"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127437"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127421"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127461"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:126746"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127604"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127173"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126623"/>
            <criterion comment="ofa-2.6.32-400.36.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126932"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27249" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2007 -- Unbreakable Enterprise kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2007.html" ref_id="ELSA-2012-2007"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0879" ref_id="CVE-2012-0879"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1090" ref_id="CVE-2012-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1097" ref_id="CVE-2012-1097"/>
        <description>[2.6.32-300.21.1.el6uek]
- regset: Return -EFAULT, not -EIO, on host-side memory fault (H. Peter Anvin)
  CVE-2012-1097
- regset: Prevent null pointer reference on readonly regsets (H. Peter Anvin)
  CVE-2012-1097
- cifs: fix dentry refcount leak when opening a FIFO on lookup (Jeff Layton)
  CVE-2012-1090
- block: Fix io_context leak after failure of clone with CLONE_IO (Louis
  Rilling)  CVE-2012-0879</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:10.889-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:01.748-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:10.651-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132122 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:02.272-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:11.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:131894"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132427"/>
            <criterion comment="ofa-2.6.32-300.21.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131845"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132389"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132347"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132418"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132213"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132400"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132435"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132122"/>
            <criterion comment="ofa-2.6.32-300.21.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:132304"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:131573"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132489"/>
            <criterion comment="ofa-2.6.32-300.21.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132573"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:131591"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132203"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132123"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132338"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132130"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132319"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132424"/>
            <criterion comment="ofa-2.6.32-300.21.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132080"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27248" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1449 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1449.html" ref_id="ELSA-2013-1449"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4368" ref_id="CVE-2013-4368"/>
        <description>kernel
[2.6.18-371.1.2]
- [xen] x86: check segment descriptor read result in 64-bit OUTS emulation (Radim Krcmar) [1012958 1012959] {CVE-2013-4368}
- [md] dm snapshot: fix data corruption (Mikulas Patocka) [1004734 975353] {CVE-2013-4299}

[2.6.18-371.1.1]
- [crypto] ansi_cprng fix off by one err in non-block size request (Neil Horman) [1007692 1007693] {CVE-2013-4345}
- [fs] gfs2: yield() in shrinker to allow glock_workqueues to run (Abhijith Das) [1014714 928518]
- [net] ipv6: ipv6_create_tempaddr cleanup (Petr Holasek) [999361 999362] {CVE-2013-0343}
- [net] ipv6: remove max_addresses check from ipv6_create_tempaddr (Petr Holasek) [999361 999362] {CVE-2013-0343}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:57.608-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:01.142-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:10.388-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:49:37.484-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:49:37.484-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128524"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.1.2.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128518"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.1.2.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128808"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128415"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128756"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128387"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128807"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128080"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128751"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128517"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:129066"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:128659"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.1.2.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128663"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.1.2.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128965"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.1.2.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128371"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.1.2.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129016"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.1.2.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128978"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.1.2.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128917"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27243" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3085 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3085.html" ref_id="ELSA-2014-3085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3611" ref_id="CVE-2014-3611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" ref_id="CVE-2014-3185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" ref_id="CVE-2014-3181"/>
        <description>[2.6.39-400.215.12]
- USB: whiteheat: Added bounds checking for bulk command response (James Forshaw)  [Orabug: 19849335]  {CVE-2014-3185}
- HID: fix a couple of off-by-ones (Jiri Kosina)  [Orabug: 19849318]  {CVE-2014-3181}
- KVM: x86: Improve thread safety in pit (Andy Honig)  [Orabug: 19905687]  {CVE-2014-3611}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:07.591-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:59.791-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.644-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126643"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126515"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126639"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126260"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126156"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126562"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126324"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:125707"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126648"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126541"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126461"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126700"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27242" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3010 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3010.html" ref_id="ELSA-2014-3010"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7265" ref_id="CVE-2013-7265"/>
        <description>[2.6.32-400.34.3]
- inet: fix addr_len/msg->msg_namelen assignment in recv_error and rxpmtu functions (Hannes Frederic Sowa)  [18247290]  {CVE-2013-7263} {CVE-2013-7265}

[2.6.32-400.34.2]
- exec/ptrace: fix get_dumpable() incorrect tests (Kees Cook)  [18239033]  {CVE-2013-2929} {CVE-2013-2929}
- inet: prevent leakage of uninitialized memory to user in recv syscalls (Hannes Frederic Sowa)  [18239036]  {CVE-2013-7263} {CVE-2013-7265}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:33.289-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:59.257-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.364-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35357 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:58.886-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:10.744-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:128142"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127422"/>
            <criterion comment="ofa-2.6.32-400.34.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128079"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127975"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127872"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127787"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:128033"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127964"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127600"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127926"/>
            <criterion comment="ofa-2.6.32-400.34.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127894"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127708"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127583"/>
            <criterion comment="ofa-2.6.32-400.34.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127963"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127732"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127830"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127479"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:128005"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127356"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127510"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128035"/>
            <criterion comment="ofa-2.6.32-400.34.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127861"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27241" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1779 -- mod_nss security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>mod_nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1779.html" ref_id="ELSA-2013-1779"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4566" ref_id="CVE-2013-4566"/>
        <description>[1.0.8-19]
- Resolves: CVE-2013-4566
- Bugzilla Bug #1030265 - mod_nss: incorrect handling of NSSVerifyClient in
  directory context [rhel-6.5.z]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:37.086-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:59.031-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.237-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:06:02.923-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:06:02.923-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="mod_nss is earlier than 0:1.0.8-8.el5_10" test_ref="oval:org.mitre.oval:tst:127764"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="mod_nss is earlier than 0:1.0.8-19.el6_5" test_ref="oval:org.mitre.oval:tst:128358"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27240" version="5" class="patch">
      <metadata>
        <title>ELSA-2010-2009 -- Oracle Linux 5 Unbreakable Enterprise kernel security fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-firmware</product>
          <product>kernel-headers</product>
          <product>ofa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-2009.html" ref_id="ELSA-2010-2009"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3477" ref_id="CVE-2010-3477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3904" ref_id="CVE-2010-3904"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3067" ref_id="CVE-2010-3067"/>
        <description>Following security bugs are fixed in this errata

CVE-2010-3904
When copying data to userspace, the RDS protocol failed to verify that the user-provided address was a valid
userspace address.  A local unprivileged user could issue specially crafted socket calls to write arbitrary
values into kernel memory and potentially escalate privileges to root.

CVE-2010-3067
Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows
local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit
system call.

CVE-2010-3477
The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing
functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which
allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump
operation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.

kernel:

[2.6.32-100.21.1.el5]
- [rds] fix access issue with rds (Chris Mason) {CVE-2010-3904}
- [fuse] linux-2.6.32-fuse-return-EGAIN-if-not-connected-bug-10154489.patch
- [net] linux-2.6.32-net-sched-fix-kernel-leak-in-act_police.patch
- [aio] linux-2.6.32-aio-check-for-multiplication-overflow-in-do_io_subm.patch

ofa:

[1.5.1-4.0.23]
- Fix rds permissions checks during copies

[1.5.1-4.0.21]
- Update to BXOFED 1.5.1-1.3.6-5</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:40.641-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:58.594-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.066-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36337 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:01.767-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:10.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-100.21.1.el5" test_ref="oval:org.mitre.oval:tst:134338"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-100.21.1.el5" test_ref="oval:org.mitre.oval:tst:134379"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-100.21.1.el5" test_ref="oval:org.mitre.oval:tst:134708"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-100.21.1.el5" test_ref="oval:org.mitre.oval:tst:134574"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-100.21.1.el5" test_ref="oval:org.mitre.oval:tst:134397"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-100.21.1.el5" test_ref="oval:org.mitre.oval:tst:134856"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-100.21.1.el5" test_ref="oval:org.mitre.oval:tst:134804"/>
          <criterion comment="ofa-2.6.32-100.21.1.el5 is earlier than 0:1.5.1-4.0.23" test_ref="oval:org.mitre.oval:tst:134358"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27239" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0122 -- tcl security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tcl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0122.html" ref_id="ELSA-2013-0122"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4772" ref_id="CVE-2007-4772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6067" ref_id="CVE-2007-6067"/>
        <description>[8.4.13-6]

- Fixed infinite loop in regex NFA optimization code

  Resolves: CVE-2007-4772

- Fixed O(N^2) compile time (and huge memory requirements) for some regexps

  Resolves: CVE-2007-6067



[8.4.13-5]

- Threaded / nonthreaded versions of tcl are now switchable through alternatives

  Resolves: rhbz#478961</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:22.830-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:58.345-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:08.944-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:12:35.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:12:35.567-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tcl is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:129715"/>
          <criterion comment="tcl-devel is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:130706"/>
          <criterion comment="tcl-html is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:130291"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27237" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0742 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0742.html" ref_id="ELSA-2014-0742"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1533" ref_id="CVE-2014-1533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1538" ref_id="CVE-2014-1538"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1541" ref_id="CVE-2014-1541"/>
        <description>[24.6.0-1.0.1.el6_5]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.6.0-1]
- Update to 24.6.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:25.479-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:57.584-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:08.511-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:41:48.641-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:41:48.641-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127418"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127117"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27232" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0108-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0108-1.html" ref_id="ELSA-2014-0108-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4494" ref_id="CVE-2013-4494"/>
        <description>kernel
[2.6.18-371.4.1.0.1]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:43.243-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:55.347-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:07.381-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35449 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:24.548-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:09.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128004"/>
          <criterion comment="ocfs2-2.6.18-371.4.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128017"/>
          <criterion comment="oracleasm-2.6.18-371.4.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127989"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127763"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128179"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128062"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128106"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128169"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128074"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128147"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127215"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127814"/>
          <criterion comment="ocfs2-2.6.18-371.4.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128110"/>
          <criterion comment="ocfs2-2.6.18-371.4.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127703"/>
          <criterion comment="ocfs2-2.6.18-371.4.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127870"/>
          <criterion comment="oracleasm-2.6.18-371.4.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127942"/>
          <criterion comment="oracleasm-2.6.18-371.4.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127881"/>
          <criterion comment="oracleasm-2.6.18-371.4.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27227" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3083 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3083.html" ref_id="ELSA-2014-3083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4653" ref_id="CVE-2014-4653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4654" ref_id="CVE-2014-4654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4655" ref_id="CVE-2014-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5077" ref_id="CVE-2014-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3122" ref_id="CVE-2014-3122"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2596" ref_id="CVE-2013-2596"/>
        <description>kernel-uek
        [2.6.32-400.36.9uek]
        - ALSA: control: Don't access controls outside of protected regions (Lars-Peter Clausen)  [Orabug: 19817787]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - ALSA: control: Fix replacing user controls (Lars-Peter Clausen)  [Orabug: 19817749]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - mm: try_to_unmap_cluster() should lock_page() before mlocking (Vlastimil Babka)  [Orabug: 19817324]  {CVE-2014-3122}
        - vm: convert fb_mmap to vm_iomap_memory() helper (Linus Torvalds)  [Orabug: 19816564]  {CVE-2013-2596}
        - vm: add vm_iomap_memory() helper function (Linus Torvalds)  [Orabug: 19816564]  {CVE-2013-2596}
        - net: sctp: inherit auth_capable on INIT collisions (Daniel Borkmann)  [Orabug: 19816069]  {CVE-2014-5077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:08.273-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:53.829-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:06.658-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126513 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:26.871-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:08.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126748"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126651"/>
            <criterion comment="ofa-2.6.32-400.36.9.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126752"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126669"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126916"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126789"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126712"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126888"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126838"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126201"/>
            <criterion comment="ofa-2.6.32-400.36.9.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126513"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126521"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126839"/>
            <criterion comment="ofa-2.6.32-400.36.9.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126731"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126342"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126428"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126902"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126709"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126862"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126730"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126543"/>
            <criterion comment="ofa-2.6.32-400.36.9.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126821"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27226" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3053 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3053.html" ref_id="ELSA-2014-3053"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196" ref_id="CVE-2014-0196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3144" ref_id="CVE-2014-3144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3145" ref_id="CVE-2014-3145"/>
        <description>[2.6.39-400.215.6]
- filter: prevent nla extensions to peek beyond the end of the message (Mathias Krause)  [Orabug: 19315782]  {CVE-2014-3144} {CVE-2014-3145}

[2.6.39-400.215.5]
- n_tty: Fix n_tty_write crash when echoing in raw mode (Peter Hurley)  [Orabug: 18756449]  {CVE-2014-0196} {CVE-2014-0196}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:33.771-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:53.241-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:06.321-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126203"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:127150"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126819"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126614"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126818"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:127153"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126775"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126609"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126882"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:127106"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:127121"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126497"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27223" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1823 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1823.html" ref_id="ELSA-2013-1823"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5609" ref_id="CVE-2013-5609"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5612" ref_id="CVE-2013-5612"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5613" ref_id="CVE-2013-5613"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5614" ref_id="CVE-2013-5614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5616" ref_id="CVE-2013-5616"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5618" ref_id="CVE-2013-5618"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6671" ref_id="CVE-2013-6671"/>
        <description>[24.2.0-1.0.1.el6_5]

- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

- Make sure build with nspr-devel >= 4.10.0



[24.2.0-1]

- Update to 24.2.0 ESR



[24.1.0-1]

- Update to 24.1.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:50.398-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:51.093-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:05.430-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:19:20.019-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:19:20.019-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128335"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128150"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27221" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0740 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0740.html" ref_id="ELSA-2014-0740"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7339" ref_id="CVE-2013-7339"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <description>kernel
[2.6.18-371.9.1]
- [nfs] sunrpc: don't use a credential with extra groups (Mateusz Guzik) [1095062 976201]
- [scsi] lpfc: Remove NDLP reference put in lpfc_cmpl_els_logo_acc (Rob Evers) [1096061 1075228]
- [infiniband] rds: dereference of a NULL device (Jacob Tanenbaum) [1079216 1079217] {CVE-2013-7339}
- [kernel] futex: check relative timeouts for overflow (Denys Vlasenko) [1091832 1084168]
- [virt] kvm: correctly detect KVM when hv emulation is enalbed (Jason Wang) [1094152 985767]
- [security] Fix spurious warnings in security_ops_task_setrlimit (Mateusz Guzik) [1092869 916235]
- [block] floppy: don't write kernel-only members to FDRAWCMD output (Denys Vlasenko) [1094302 1094303] {CVE-2014-1738 CVE-2014-1737}
- [block] floppy: ignore kernel-only members in FDRAWCMD input (Denys Vlasenko) [1094302 1094303] {CVE-2014-1738 CVE-2014-1737}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:23.390-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:50.419-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:05.051-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:49:27.953-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:49:27.953-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127353"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.9.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127599"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.9.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127026"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127486"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127405"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127424"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127172"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127519"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127539"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127489"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127435"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:127482"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.9.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127151"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.9.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127323"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.9.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127458"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.9.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127532"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.9.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127528"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.9.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127568"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27215" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3069 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3069.html" ref_id="ELSA-2014-3069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4667" ref_id="CVE-2014-4667"/>
        <description>kernel-uek
[2.6.32-400.36.7uek]
- sctp: Fix sk_ack_backlog wrap-around problem (Xufeng Zhang)  [Orabug: 19404246]  {CVE-2014-4667}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:06.731-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:49.127-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:04.206-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126584 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:24.885-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:08.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126764"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127021"/>
            <criterion comment="ofa-2.6.32-400.36.7.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126584"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126597"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:127016"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126577"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126783"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126529"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126685"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126837"/>
            <criterion comment="ofa-2.6.32-400.36.7.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126856"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126760"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126247"/>
            <criterion comment="ofa-2.6.32-400.36.7.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126758"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126980"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126832"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126920"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126679"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126873"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126028"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126417"/>
            <criterion comment="ofa-2.6.32-400.36.7.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126167"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27213" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0257 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0257.html" ref_id="ELSA-2011-0257"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4539" ref_id="CVE-2010-4539"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4644" ref_id="CVE-2010-4644"/>
        <description>[1.6.11-7.1]
- add security fixes for CVE-2010-4644, CVE-2010-4539 (#672676)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:41.489-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:48.866-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:04.058-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:33:50.782-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:33:50.782-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:134199"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:133842"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:133994"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:134310"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:134117"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:134288"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27212" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1476 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1476.html" ref_id="ELSA-2013-1476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5590" ref_id="CVE-2013-5590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5595" ref_id="CVE-2013-5595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5597" ref_id="CVE-2013-5597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5599" ref_id="CVE-2013-5599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5600" ref_id="CVE-2013-5600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5601" ref_id="CVE-2013-5601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5602" ref_id="CVE-2013-5602"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5604" ref_id="CVE-2013-5604"/>
        <description>firefox
[17.0.10-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[17.0.10-1]
- Update to 17.0.10 ESR

xulrunner
[17.0.10-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.10-1]
- Update to 17.0.10 ESR

[17.0.9-2]
- Added patch for rhbz#983488 - Resizing window changes window
  size to 0 with third party window manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:19.562-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:48.112-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:03.682-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:16:44.957-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:16:44.957-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128639"/>
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128750"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128741"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128559"/>
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128729"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128727"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27208" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0185 -- openswan security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0185.html" ref_id="ELSA-2014-0185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6466" ref_id="CVE-2013-6466"/>
        <description>[2.6.32-27.2]
- Resolves: rhbz#1050337 (CVE-2013-6466 refix for delete/notify code)

[2.6.32-27.1]
- Resolves: rhbz#1050337 (CVE-2013-6466)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:28.149-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:47.739-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:03.423-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:39:21.029-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:39:21.029-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:127662"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:127960"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:127971"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:127808"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27204" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1323 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1323.html" ref_id="ELSA-2012-1323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3430" ref_id="CVE-2012-3430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2319" ref_id="CVE-2012-2319"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3510" ref_id="CVE-2012-3510"/>
        <description>kernel
[2.6.18-308.16.1.el5]
- Revert: [fs] nfsd4: Remove check for a 32-bit cookie in nfsd4_readdir() (Eric Sandeen) [847943 784191]
- Revert: [fs] add new FMODE flags: FMODE_32bithash and FMODE_64bithash (Eric Sandeen) [847943 784191]
- Revert: [fs] nfsd: rename int access to int may_flags in nfsd_open() (Eric Sandeen) [847943 784191]
- Revert: [fs] nfsd: vfs_llseek() with 32 or 64 bit offsets (hashes) (Eric Sandeen) [847943 784191]
- Revert: [fs] vfs: add generic_file_llseek_size (Eric Sandeen) [847943 784191]
- Revert: [s390/ppc64] add is_compat_task() for s390 and ppc64 (Eric Sandeen) [847943 784191]
- Revert: [fs] ext3: return 32/64-bit dir name hash according to usage type (Eric Sandeen) [847943 784191]
- Revert: [fs] ext4: improve llseek error handling for large seek offsets (Eric Sandeen) [847943 784191]
- Revert: [fs] ext4: return 32/64-bit dir name hash according to usage type (Eric Sandeen) [847943 784191]
- Revert: [fs] vfs: allow custom EOF in generic_file_llseek code (Eric Sandeen) [847943 784191]
- Revert: [fs] ext4: use core vfs llseek code for dir seeks (Eric Sandeen) [847943 784191]
- Revert: [fs] ext3: pass custom EOF to generic_file_llseek_size() (Eric Sandeen) [847943 784191]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:25.195-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:46.166-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:02.486-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:55:26.575-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:55:26.575-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:130975"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.16.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130919"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.16.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130684"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:130413"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:131191"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:131044"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:131158"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:131035"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:130663"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:131095"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:130680"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:131194"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.16.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130998"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.16.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131071"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-308.16.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130197"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.16.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131173"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.16.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130785"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-308.16.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130743"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27202" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1302 -- xinetd security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1302.html" ref_id="ELSA-2013-1302"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0862" ref_id="CVE-2012-0862"/>
        <description>[2:2.3.14-19]

- Correctly backport patches that fix the descriptor leakage

- Related: #852274



[-2:2.3.14-18]

- Fix leaking file descriptors (#852274)

- Fix: Service disabled due to bind failure (#811000)

- CVE-2012-0862 xinetd: enables unintentional services over tcpmux port (#788795)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:02.221-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:45.688-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:02.214-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:11:10.817-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:11:10.817-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="xinetd is earlier than 0:2.3.14-19.el5" test_ref="oval:org.mitre.oval:tst:128761"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27197" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1012 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1012.html" ref_id="ELSA-2014-1012"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0237" ref_id="CVE-2014-0237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0238" ref_id="CVE-2014-0238"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3479" ref_id="CVE-2014-3479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3480" ref_id="CVE-2014-3480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3515" ref_id="CVE-2014-3515"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4049" ref_id="CVE-2014-4049"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4721" ref_id="CVE-2014-4721"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1571" ref_id="CVE-2012-1571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6712" ref_id="CVE-2013-6712"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1943" ref_id="CVE-2014-1943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270" ref_id="CVE-2014-2270"/>
        <description>[5.3.3-27.1]
        - core: type confusion issue in phpinfo(). CVE-2014-4721
        - date: fix heap-based buffer over-read in DateInterval. CVE-2013-6712
        - core: fix heap-based buffer overflow in DNS TXT record parsing.
          CVE-2014-4049
        - core: unserialize() SPL ArrayObject / SPLObjectStorage type
          confusion flaw. CVE-2014-3515
        - fileinfo: out-of-bounds memory access in fileinfo. CVE-2014-2270
        - fileinfo: unrestricted recursion in handling of indirect type
          rules. CVE-2014-1943
        - fileinfo: out of bounds read in CDF parser. CVE-2012-1571
        - fileinfo: cdf_check_stream_offset boundary check. CVE-2014-3479
        - fileinfo: cdf_count_chain insufficient boundary check. CVE-2014-3480
        - fileinfo: cdf_unpack_summary_info() excessive looping
          DoS. CVE-2014-0237
        - fileinfo: CDF property info parsing nelements infinite
          loop. CVE-2014-0238</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:10.403-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:44.222-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:01.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126976"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126968"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126875"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126791"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126884"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126282"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126954"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:127004"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126678"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126642"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:127060"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126425"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126948"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126774"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126656"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126841"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126404"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126870"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126816"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:127001"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126988"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126705"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126847"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127002"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127030"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126895"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126525"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126865"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126989"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126990"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127057"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126767"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126581"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127008"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126455"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127061"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126698"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126583"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127041"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126606"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126840"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126956"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126316"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126753"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126400"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126608"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126174"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127049"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27196" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0731 -- expat security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>expat</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0731.html" ref_id="ELSA-2012-0731"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0876" ref_id="CVE-2012-0876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1148" ref_id="CVE-2012-1148"/>
        <description>[2.0.1-11]
- use symbol version for XML_SetHashSalt (CVE-2012-0876, #816306)

[2.0.1-10]
- add security fix for CVE-2012-1148 (#811825)
- add security fix for CVE-2012-0876 (#811833)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:10.566-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:43.967-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:01.316-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:23:55.226-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:23:55.226-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="expat is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:131762"/>
            <criterion comment="expat-devel is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:131276"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="expat is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:131948"/>
            <criterion comment="expat-devel is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:131949"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27194" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-1061-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1061-1.html" ref_id="ELSA-2012-1061-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3375" ref_id="CVE-2012-3375"/>
        <description>[2.6.18-308.11.1.0.1.el5]
- [net] bonding: fix carrier detect when bond is down [orabug 12377284]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] shrink_zone patch (John Sobecki,Chris Mason) [orabug 6086839]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
  RDS: Fix BUG_ONs to not fire when in a tasklet
  ipoib: Fix lockup of the tx queue
  RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
  RDS: Properly unmap when getting a remote access error (Tina Yang)
  RDS: Fix locking in rds_send_drop_to()
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
+- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory  for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make  configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:40.251-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:43.251-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:00.922-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36042 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:29.393-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:07.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131491"/>
          <criterion comment="ocfs2-2.6.18-308.11.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131470"/>
          <criterion comment="oracleasm-2.6.18-308.11.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131490"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131575"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131687"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130709"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131547"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131268"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131582"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131431"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131616"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:131225"/>
          <criterion comment="ocfs2-2.6.18-308.11.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130941"/>
          <criterion comment="ocfs2-2.6.18-308.11.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131626"/>
          <criterion comment="ocfs2-2.6.18-308.11.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:131446"/>
          <criterion comment="oracleasm-2.6.18-308.11.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131667"/>
          <criterion comment="oracleasm-2.6.18-308.11.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131293"/>
          <criterion comment="oracleasm-2.6.18-308.11.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:131699"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27193" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1447 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1447.html" ref_id="ELSA-2013-1447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3829" ref_id="CVE-2013-3829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4002" ref_id="CVE-2013-4002"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5772" ref_id="CVE-2013-5772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5774" ref_id="CVE-2013-5774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5778" ref_id="CVE-2013-5778"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5780" ref_id="CVE-2013-5780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5782" ref_id="CVE-2013-5782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5783" ref_id="CVE-2013-5783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5784" ref_id="CVE-2013-5784"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5790" ref_id="CVE-2013-5790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5800" ref_id="CVE-2013-5800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5802" ref_id="CVE-2013-5802"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5803" ref_id="CVE-2013-5803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5804" ref_id="CVE-2013-5804"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5809" ref_id="CVE-2013-5809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5814" ref_id="CVE-2013-5814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5817" ref_id="CVE-2013-5817"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5820" ref_id="CVE-2013-5820"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5823" ref_id="CVE-2013-5823"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5825" ref_id="CVE-2013-5825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5829" ref_id="CVE-2013-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5830" ref_id="CVE-2013-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5838" ref_id="CVE-2013-5838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5840" ref_id="CVE-2013-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5842" ref_id="CVE-2013-5842"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5849" ref_id="CVE-2013-5849"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5850" ref_id="CVE-2013-5850"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5851" ref_id="CVE-2013-5851"/>
        <description>[1.7.0.45-2.4.3.1.0.1.el5_10]
- Add oracle-enterprise.patch
- Fix DISTRO_NAME to 'Enterprise Linux'

[1.7.0.45-2.4.3.1.el5]
- Updated to icedtea 2.4.3
- Resolves: rhbz#1017623

[1.7.0.45-2.4.3.0.el5]
- fixed and updated tapset
- removed bootstrap
- source 11 redeclared to 1111
- added source12: TestCryptoLevel.java
- removed upstreamed patch103 java-1.7.0-openjdk-arm-fixes.patch
- removed unnecessary patch112 java-1.7.0-openjdk-doNotUseDisabledEcc.patch
- added patch120: java-1.7.0-openjdk-freetype-check-fix.patch
- fixed nss
- cleaned sources
- Resolves: rhbz#1017623

[1.7.0.25-2.4.1.4.el5]
- updated to icedtea 2.4.1
- improoved handling of patch111 - nss-config-2.patch
- backported uniquesuffix from 6.5
- Resolves: rhbz#978421</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:28.115-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:40.970-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:00.157-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:15:33.237-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:15:33.237-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.45-2.4.3.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128841"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.45-2.4.3.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128718"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.45-2.4.3.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:129027"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.45-2.4.3.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:129042"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.45-2.4.3.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128867"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27192" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1110 -- glibc security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1110.html" ref_id="ELSA-2014-1110"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0475" ref_id="CVE-2014-0475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119" ref_id="CVE-2014-5119"/>
        <description>An off-by-one heap-based buffer overflow flaw was found in glibc's internal
          __gconv_translit_find() function. An attacker able to make an application
          call the iconv_open() function with a specially crafted argument could
          possibly use this flaw to execute arbitrary code with the privileges of
          that application. (CVE-2014-5119)

          A directory traveral flaw was found in the way glibc loaded locale files.
          An attacker able to make an application use a specially crafted locale name
          value (for example, specified in an LC_* environment variable) could
          possibly use this flaw to execute arbitrary code with the privileges of
          that application. (CVE-2014-0475)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:27.598-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:40.605-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:00.004-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126987"/>
            <criterion comment="glibc-common is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126587"/>
            <criterion comment="glibc-devel is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126668"/>
            <criterion comment="glibc-headers is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126358"/>
            <criterion comment="glibc-utils is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126898"/>
            <criterion comment="nscd is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126586"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126330"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126983"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126239"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126649"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126715"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126951"/>
            <criterion comment="nscd is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126479"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27186" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1123 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1123.html" ref_id="ELSA-2012-1123"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3817" ref_id="CVE-2012-3817"/>
        <description>[32:9.8.2-0.10.rc1.2]
- fix CVE-2012-3817</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:20.427-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:39.635-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:59.507-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:08:38.406-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:08:38.406-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:130891"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:130911"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131404"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131385"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131376"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:130568"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131294"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131468"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131251"/>
            <criterion comment="bind-chroot is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131277"/>
            <criterion comment="bind-devel is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131557"/>
            <criterion comment="bind-libs is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131058"/>
            <criterion comment="bind-sdb is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131545"/>
            <criterion comment="bind-utils is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131456"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27185" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0599 -- xen security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0599.html" ref_id="ELSA-2013-0599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6075" ref_id="CVE-2012-6075"/>
        <description>[3.0.3-142.el5_9.2]
- e1000: discard packets that are too long if !SBP and !LPE (rhbz 910843)
- e1000: discard oversized packets based on SBP|LPE (rhbz 910843)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:53.172-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:39.454-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:59.405-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:56:00.017-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:56:00.017-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xen is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:129904"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:129608"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:129795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27177" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1457 -- libgcrypt security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1457.html" ref_id="ELSA-2013-1457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4242" ref_id="CVE-2013-4242"/>
        <description>[1.4.5-11]
- fix CVE-2013-4242 GnuPG/libgcrypt susceptible to cache side-channel attack

[1.4.5-10]
- Add GCRYCTL_SET_ENFORCED_FIPS_FLAG command</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:16.685-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:37.910-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:58.240-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:50:31.348-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:50:31.348-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:128783"/>
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:128802"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:128691"/>
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:128806"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27176" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0131 -- gnome-vfs2 security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnome-vfs2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0131.html" ref_id="ELSA-2013-0131"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2473" ref_id="CVE-2009-2473"/>
        <description>[2.16.2-10.el5]

- Prevent trash applet crashing (#848822)



[2.16.2-9.el5]

- Prevent deleting items linking out of the trash (#586015)

- Do not stat every file on an ClearCase mvfs filesystem (#822817)

- Do not silently skip directory having no read permission during copy (#772307)

- Allow trashing symlink to filesystem root that does not support trashing (#621394)

- CVE-2009-2473 gnome-vfs2 embedded neon: billion laughs DoS attack (#540548)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:56.637-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:37.743-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:58.055-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:51:26.695-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:51:26.695-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnome-vfs2 is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:130668"/>
          <criterion comment="gnome-vfs2-devel is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:130511"/>
          <criterion comment="gnome-vfs2-smb is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:130527"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27165" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0568 -- dbus-glib security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dbus-glib</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0568.html" ref_id="ELSA-2013-0568"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0292" ref_id="CVE-2013-0292"/>
        <description>[0.73-11]

- Add patch to fix CVE-2013-0292

- Resolves: #913072</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:48.490-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:36.228-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:57.045-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:19:37.768-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:19:37.768-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:130294"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:130165"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:129651"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:130093"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27161" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0387 -- firefox security and bug fix update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0387.html" ref_id="ELSA-2012-0387"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0451" ref_id="CVE-2012-0451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0455" ref_id="CVE-2012-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0456" ref_id="CVE-2012-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0457" ref_id="CVE-2012-0457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0458" ref_id="CVE-2012-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0459" ref_id="CVE-2012-0459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0460" ref_id="CVE-2012-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0461" ref_id="CVE-2012-0461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0462" ref_id="CVE-2012-0462"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0464" ref_id="CVE-2012-0464"/>
        <description>firefox:

[10.0.3-1.0.1.el6_2]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[10.0.3-1]
- Update to 10.0.3 ESR

xulrunner:

[10.0.3-1.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with
- xulrunner-oracle-default-prefs.js

[10.0.3-1]
- Update to 10.0.3 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:19.969-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:35.190-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:56.438-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:03:16.869-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:03:16.869-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.3-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132321"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132434"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132495"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.3-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132278"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132431"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132350"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27158" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3054 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3054.html" ref_id="ELSA-2014-3054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196" ref_id="CVE-2014-0196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3144" ref_id="CVE-2014-3144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3145" ref_id="CVE-2014-3145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6647" ref_id="CVE-2012-6647"/>
        <description>kernel-uek
[2.6.32-400.36.6uek]
- filter: prevent nla extensions to peek beyond the end of the message (Mathias Krause)  [Orabug: 19315783]  {CVE-2014-3144} {CVE-2014-3145}
- futex: Forbid uaddr == uaddr2 in futex_wait_requeue_pi() (Darren Hart)  [Orabug: 19315318]  {CVE-2012-6647}

[2.6.32-400.36.5uek]
- n_tty: Fix n_tty_write crash when echoing in raw mode (Peter Hurley)  [Orabug: 18756450]  {CVE-2014-0196} {CVE-2014-0196}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:13.186-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:33.205-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:55.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127137 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:27.200-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:07.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126978"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127039"/>
            <criterion comment="ofa-2.6.32-400.36.6.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126658"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:127042"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126906"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:127099"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:127143"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126348"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126631"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127075"/>
            <criterion comment="ofa-2.6.32-400.36.6.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127137"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126628"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127157"/>
            <criterion comment="ofa-2.6.32-400.36.6.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126779"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:127126"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126382"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126770"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:127069"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:127033"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126930"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126891"/>
            <criterion comment="ofa-2.6.32-400.36.6.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27139" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0134 -- freeradius2 security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>freeradius2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0134.html" ref_id="ELSA-2013-0134"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4966" ref_id="CVE-2011-4966"/>
        <description>[2.1.12-5]

- resolves: bug#855308

  CVE-2012-3547 freeradius: Stack-based buffer overflow by processing

  certain expiration date fields of a certificate during x509 certificate

  validation</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:32.127-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:27.207-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:53.747-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:09:42.028-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:09:42.028-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="freeradius2 is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130445"/>
          <criterion comment="freeradius2-krb5 is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130525"/>
          <criterion comment="freeradius2-ldap is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130677"/>
          <criterion comment="freeradius2-mysql is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130504"/>
          <criterion comment="freeradius2-perl is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130656"/>
          <criterion comment="freeradius2-postgresql is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130409"/>
          <criterion comment="freeradius2-python is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130538"/>
          <criterion comment="freeradius2-unixODBC is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:129981"/>
          <criterion comment="freeradius2-utils is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:130459"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27136" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3082 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3082.html" ref_id="ELSA-2014-3082"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4653" ref_id="CVE-2014-4653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4654" ref_id="CVE-2014-4654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4655" ref_id="CVE-2014-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5077" ref_id="CVE-2014-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3601" ref_id="CVE-2014-3601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3122" ref_id="CVE-2014-3122"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2596" ref_id="CVE-2013-2596"/>
        <description>[2.6.39-400.215.11]
        - ALSA: control: Don't access controls outside of protected regions (Lars-Peter Clausen)  [Orabug: 19817786]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - ALSA: control: Fix replacing user controls (Lars-Peter Clausen)  [Orabug: 19817748]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601) (Michael S. Tsirkin)  [Orabug: 19817647]  {CVE-2014-3601}
        - mm: try_to_unmap_cluster() should lock_page() before mlocking (Vlastimil Babka)  [Orabug: 19817323]  {CVE-2014-3122}
        - vm: convert fb_mmap to vm_iomap_memory() helper (Linus Torvalds)  [Orabug: 19816563]  {CVE-2013-2596}
        - vm: add vm_iomap_memory() helper function (Linus Torvalds)  [Orabug: 19816563]  {CVE-2013-2596}
        - net: sctp: inherit auth_capable on INIT collisions (Daniel Borkmann)  [Orabug: 19816068]  {CVE-2014-5077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:26.722-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:26.218-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:53.186-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126675"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126811"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126647"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126741"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126927"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126672"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126708"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126750"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126845"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126526"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126424"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126876"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27135" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1364 -- bind97 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1364.html" ref_id="ELSA-2012-1364"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5166" ref_id="CVE-2012-5166"/>
        <description>[32:9.7.0-10.P2.4]
- fix CVE-2012-5166</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:15.823-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:25.995-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:53.038-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:58:42.526-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:58:42.526-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 0:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:130746"/>
          <criterion comment="bind97-chroot is earlier than 0:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:131146"/>
          <criterion comment="bind97-devel is earlier than 0:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:131108"/>
          <criterion comment="bind97-libs is earlier than 0:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:131110"/>
          <criterion comment="bind97-utils is earlier than 0:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:130880"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27134" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1635 -- firefox security update</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>xulrunner-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1635.html" ref_id="ELSA-2014-1635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1574" ref_id="CVE-2014-1574"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1576" ref_id="CVE-2014-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1577" ref_id="CVE-2014-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1578" ref_id="CVE-2014-1578"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1581" ref_id="CVE-2014-1581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1583" ref_id="CVE-2014-1583"/>
        <description>firefox
[31.2.0-3.0.1.el7_0]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[31.2.0-3]
- Update to 31.2.0 ESR
- Fix for mozbz#1042889

[31.1.0-7]
- Enable WebM on all arches

xulrunner
[31.2.0-1.0.1]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[31.2.0-1]
- Update to 31.2.0

[31.1.0-3]
- move /sdk/bin to xulrunner libdir

[31.1.0-2]
- Sync preferences with Firefox package

[31.1.0-1]
- Update to 31.1.0 ESR

[31.0-2]
- Fix header wrapper for aarch64

[31.0-1]
- Update to 31.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:15.310-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27134 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:47.416-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:38.154-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126202"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:125364"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.2.0-3.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126173"/>
            <criterion comment="xulrunner is earlier than 0:31.2.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126222"/>
            <criterion comment="xulrunner-devel is earlier than 0:31.2.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27133" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1512 -- libxml2 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1512.html" ref_id="ELSA-2012-1512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5134" ref_id="CVE-2012-5134"/>
        <description>[2.7.6-8.0.1.el6_3.4 ]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-8.el6_3.4]
- fix out of range heap access (CVE-2012-5134)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:46.413-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:25.769-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.857-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:26:15.530-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:26:15.530-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.0.1.el5_8.6" test_ref="oval:org.mitre.oval:tst:130537"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.0.1.el5_8.6" test_ref="oval:org.mitre.oval:tst:130705"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.0.1.el5_8.6" test_ref="oval:org.mitre.oval:tst:130152"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130357"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130386"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130674"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130385"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27130" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0626 -- openssl097a and openssl098e security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0626.html" ref_id="ELSA-2014-0626"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224" ref_id="CVE-2014-0224"/>
        <description>[0.9.8e-18.0.1.el6_5.2]
- Updated the description

[0.9.8e-18.2]
- fix for CVE-2014-0224 - SSL/TLS MITM vulnerability

[0.9.8e-18]
- fix for CVE-2012-2110 - memory corruption in asn1_d2i_read_bio() (#814185)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:38.453-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:24.759-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.334-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:45:19.767-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:45:19.767-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" test_ref="oval:org.mitre.oval:tst:127483"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="openssl098e is earlier than 0:0.9.8e-18.0.1.el6_5.2" test_ref="oval:org.mitre.oval:tst:127613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27126" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1407 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1407.html" ref_id="ELSA-2012-1407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4194" ref_id="CVE-2012-4194"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4195" ref_id="CVE-2012-4195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4196" ref_id="CVE-2012-4196"/>
        <description>firefox
[10.0.10-1.0.1.el6_3]
- Replaced firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.10-1]
- Update to 10.0.10 ESR

[10.0.8-2]
- Fixed rhbz#865284 - add the storage.nfs_filesystem
  config key to property list
- disable OOP for wrapped plugins (nspluginwrapper)

xulrunner
[10.0.10-1.0.1.el6_3]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.10-1]
- Added patches from 10.0.10 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:40.629-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:22.631-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.126-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:54:48.119-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:54:48.119-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130508"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130740"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130883"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130979"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130473"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27124" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0301 -- ImageMagick security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0301.html" ref_id="ELSA-2012-0301"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4167" ref_id="CVE-2010-4167"/>
        <description>[6.2.8.0-12.el5]
- Add fix for CVE-2010-4167 (767142)

[6.2.8.0-11.el5]
Fix assertion failed when using 'identify -verbose' when theres no
  image information available (502626)

[6.2.8.0-10.el5]
Fix memory allocation failure when using color option (616538)
  Fix hang when converting broken GIF (693989)
  Fix conversion of rotated landscape PDF (694922)

[6.2.8.0-9.el5]
Fix a deadlock with semaphore (530592)

[6.2.8.0-8.el5]
- Fix page size argument parsing (580535)

[6.2.8.0-7.el5]
- Fix SGI image decoding (498063)

[6.2.8.0-6.el5]
- Add fix for CVE-2009-1882 (504305)

[6.2.8.0-5.el5]
- update quantum memory patch (necessary for CVE fixes)
- backport functionality for SetImageExtent (necessary for CVE fixes)
- Add patch for CVE-2008-1096 (#286411)
- Add patch for CVE-2008-1097 (#285861)
- update patch for CVE-2007-4986</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:27.365-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:20.999-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.018-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:26:58.937-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:26:58.937-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:132520"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:132610"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:132639"/>
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:132422"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:132665"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27122" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1036 -- postgresql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1036.html" ref_id="ELSA-2012-1036"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2143" ref_id="CVE-2012-2143"/>
        <description>[8.1.23-5]
- Back-port upstream fix for CVE-2012-2143
Resolves: #830721</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:11.999-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:20.084-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:51.650-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:29:41.620-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:29:41.620-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postgresql is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131625"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131586"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131863"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131853"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131551"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131606"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131879"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131841"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131600"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:131248"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27118" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1306 -- bash security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1306.html" ref_id="ELSA-2014-1306"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7169" ref_id="CVE-2014-7169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7186" ref_id="CVE-2014-7186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7187" ref_id="CVE-2014-7187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271" ref_id="CVE-2014-6271"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

It was found that the fix for CVE-2014-6271 was incomplete, and Bash still
allowed certain characters to be injected into other environments via
specially crafted environment variables. An attacker could potentially use
this flaw to override or bypass environment restrictions to execute shell
commands. Certain services and applications allow remote unauthenticated
attackers to provide environment variables, allowing them to exploit this
issue. (CVE-2014-7169)

Applications which directly create bash functions as environment variables
need to be made aware of changes to the way names are handled by this
update. Note that certain services, screen sessions, and tmux sessions may
need to be restarted, and affected interactive users may need to re-login.
Installing these updated packages without restarting services will address
the vulnerability, but functionality may be impacted until affected
services are restarted. For more information see the Knowledgebase article
at &lt;A HREF="https://access.redhat.com/articles/1200223">https://access.redhat.com/articles/1200223&lt;/A>

Note: Docker users are advised to use &amp;quot;yum update&amp;quot; within their containers,
and to commit the resulting changes.

For additional information on CVE-2014-6271 and CVE-2014-7169, refer to the
aforementioned Knowledgebase article.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:30.153-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:53.905-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:45.088-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:124970"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:124279"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:124960"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:124908"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="bash RPM is earlier than 0:3.2-33.el5_11.4" test_ref="oval:org.mitre.oval:tst:124880"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27112" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3038 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3038.html" ref_id="ELSA-2014-3038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153" ref_id="CVE-2014-3153"/>
        <description>[2.6.39-400.215.2]
- futex: Make lookup_pi_state more robust (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153}
- futex: Always cleanup owner tid in unlock_pi (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153}
- futex: Validate atomic acquisition in futex_lock_pi_atomic() (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153}
- futex: Forbid uaddr1 == uaddr2 in futex_requeue(..., requeue_pi=1) (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153} {CVE-2014-3153}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:06.500-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:16.958-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:49.922-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127472"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127585"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127546"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127333"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127379"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:126659"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127179"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127634"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127234"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127552"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127589"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127651"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27106" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0624 -- openssl security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0624.html" ref_id="ELSA-2014-0624"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224" ref_id="CVE-2014-0224"/>
        <description>[0.9.8e-27.3]
- fix for CVE-2014-0224 - SSL/TLS MITM vulnerability

[0.9.8e-27.1]
- replace expired GlobalSign Root CA certificate in ca-bundle.crt</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:42.227-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:15.987-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:49.490-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:45:53.677-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:45:53.677-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:127416"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:126998"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:127631"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27102" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2513 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2513.html" ref_id="ELSA-2013-2513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" ref_id="CVE-2013-0871"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1773" ref_id="CVE-2013-1773"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0913" ref_id="CVE-2013-0913"/>
        <description>[2.6.39-400.21.1]
- SPEC: v2.6.39-400.21.1 (Maxim Uvarov)
- xen/mmu: On early bootup, flush the TLB when changing RO->RW bits Xen provided pagetables. (Konrad Rzeszutek Wilk)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:44.022-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:15.169-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:48.963-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129724"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129805"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129781"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129606"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129311"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129770"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:128935"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129789"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129713"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129546"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129296"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129566"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27093" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3039 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3039.html" ref_id="ELSA-2014-3039"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153" ref_id="CVE-2014-3153"/>
        <description>kernel-uek
[2.6.32-400.36.2uek]
- futex: Make lookup_pi_state more robust (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153}
- futex: Always cleanup owner tid in unlock_pi (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153}
- futex: Validate atomic acquisition in futex_lock_pi_atomic() (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153}
- futex: Forbid uaddr1 == uaddr2 in futex_requeue(..., requeue_pi=1) (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153} {CVE-2014-3153}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:32.999-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:12.580-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:47.428-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35271 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:23.249-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:06.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127598"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127656"/>
            <criterion comment="ofa-2.6.32-400.36.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127563"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127401"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:126690"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127639"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127578"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127580"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127454"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127620"/>
            <criterion comment="ofa-2.6.32-400.36.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126943"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127597"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127654"/>
            <criterion comment="ofa-2.6.32-400.36.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127398"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127470"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127553"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:126984"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127093"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127544"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127644"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127443"/>
            <criterion comment="ofa-2.6.32-400.36.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127226"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27092" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3023 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3023.html" ref_id="ELSA-2014-3023"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <description>kernel-uek
[2.6.32-400.34.5uek]
- aacraid: missing capable() check in compat ioctl (Dan Carpenter)  [Orabug: 18723276]  {CVE-2013-6383}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:32.493-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:12.238-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:47.247-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127645 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:24.139-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:06.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127326"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127522"/>
            <criterion comment="ofa-2.6.32-400.34.5.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127506"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127178"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127535"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127579"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127456"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127529"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127618"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127567"/>
            <criterion comment="ofa-2.6.32-400.34.5.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127335"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127427"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127660"/>
            <criterion comment="ofa-2.6.32-400.34.5.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127262"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127623"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127537"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127686"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127135"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:126785"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127666"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127645"/>
            <criterion comment="ofa-2.6.32-400.34.5.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127409"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27090" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0727 -- kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0727.html" ref_id="ELSA-2013-0727"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1796" ref_id="CVE-2013-1796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1798" ref_id="CVE-2013-1798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1797" ref_id="CVE-2013-1797"/>
        <description>[kvm-83-262.0.1.el5_9.3]
- Added kvm-add-oracle-workaround-for-libvirt-bug.patch
- Added kvm-Introduce-oel-machine-type.patch

[kvm-83-262.el5_3]
- kvm-kernel-kvm-accept-unaligned-MSR_KVM_SYSTEM_TIME-writes.patch [bz#947363]
- Resolves: bz#947363
  (RHEL.5.8.32 guest hang when installing)

[kvm-83-262.el5_2]
- kvm-kernel-KVM-Fix-for-buffer-overflow-in-handling-of-MSR_KVM_S.patch [bz#917018]
- kvm-kernel-KVM-Convert-MSR_KVM_SYSTEM_TIME-to-use-kvm_write_gue.patch [bz#917022]
- kvm-kernel-KVM-Fix-bounds-checking-in-ioapic-indirect-register-.patch [bz#917028]
- kvm-kernel-do-not-GP-on-unaligned-MSR_KVM_SYSTEM_TIME-write.patch [bz#bz917019]
- Resolves: bz#917018
  (CVE-2013-1796 kernel: kvm: buffer overflow in handling of MSR_KVM_SYSTEM_TIME [rhel-5.9.z])
- Resolves: bz#917022
  (CVE-2013-1797 kernel: kvm: after free issue with the handling of MSR_KVM_SYSTEM_TIME [rhel-5.9.z])
- Resolves: bz#917028
  (CVE-2013-1798 kernel: kvm: out-of-bounds access in ioapic indirect register reads [rhel-5.9.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:38.561-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:11.781-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:47.032-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:04:54.777-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:04:54.777-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kvm is earlier than 0:83-262.0.1.el5_9.3" test_ref="oval:org.mitre.oval:tst:129665"/>
          <criterion comment="kmod-kvm is earlier than 0:83-262.0.1.el5_9.3" test_ref="oval:org.mitre.oval:tst:129721"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-262.0.1.el5_9.3" test_ref="oval:org.mitre.oval:tst:128827"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-262.0.1.el5_9.3" test_ref="oval:org.mitre.oval:tst:129796"/>
          <criterion comment="kvm-tools is earlier than 0:83-262.0.1.el5_9.3" test_ref="oval:org.mitre.oval:tst:128892"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27088" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0174 -- piranha security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>piranha</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0174.html" ref_id="ELSA-2014-0174"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6492" ref_id="CVE-2013-6492"/>
        <description>[0.8.4-26.1.0.1]
- Replace web/web/RedHat.gif with updated image in tarball

[0.8.4-26.1]
- Resolves: #1061903 - require authentication for all HTTP methods

[0.8.4-26]
- Resolves: #886361 - add SIGCHLD handler to pulse for lvs mode</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:24.621-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:11.476-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:46.887-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:48:07.998-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:48:07.998-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="piranha is earlier than 0:0.8.4-26.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:127545"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27081" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0027 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0027.html" ref_id="ELSA-2014-0027"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5878" ref_id="CVE-2013-5878"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5884" ref_id="CVE-2013-5884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5893" ref_id="CVE-2013-5893"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5896" ref_id="CVE-2013-5896"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5907" ref_id="CVE-2013-5907"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5910" ref_id="CVE-2013-5910"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0368" ref_id="CVE-2014-0368"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0373" ref_id="CVE-2014-0373"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0376" ref_id="CVE-2014-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0411" ref_id="CVE-2014-0411"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0416" ref_id="CVE-2014-0416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0422" ref_id="CVE-2014-0422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0423" ref_id="CVE-2014-0423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0428" ref_id="CVE-2014-0428"/>
        <description>[1.7.0.51-2.4.4.1.0.1.el5_10]
- Add oracle-enterprise.patch
- Fix DISTRO_NAME to 'Enterprise Linux'

[1.7.0.51-2.4.4.1.el5]
- updated to security icedtea 2.4.4
 - icedtea_version set to 2.4.4
 - updatever bumped to       51
 - release reset to 1
- build requires: java-devel >= 1:1.6.0 changed java7-devel
- Resolves: rhbz#1050192</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:27.715-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:07.984-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:46.284-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:22:58.175-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:22:58.175-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.51-2.4.4.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127769"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.51-2.4.4.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128188"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.51-2.4.4.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127727"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.51-2.4.4.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127996"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.51-2.4.4.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27079" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0322 -- net-snmp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0322.html" ref_id="ELSA-2014-0322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6151" ref_id="CVE-2012-6151"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2285" ref_id="CVE-2014-2285"/>
        <description>[5.3.2.2-22.0.2.el5_10.1]
- hrProcessorLoad returns incorrect values for CPUs greater than 100 (Jason Luan) [Orabug 17792842]
- snmptrapd: Fix crash due to access of freed memory (John Haxby) [orabug 14391194]
- suppress spurious asserts on 32bit [Greg Marsden]

[5.3.2.2-20.1]
- Fixed CVE-2012-6151: snmpd crashing when AgentX subagent disconnects in
  the middle of request processing (#1073224)
- Fixed CVE-2014-2285: snmptrapd crash when using a trap with empty community
  string (#1073224)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:19.520-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:07.435-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:46.021-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:24:19.383-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:24:19.383-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="net-snmp is earlier than 0:5.3.2.2-22.0.2.el5_10.1" test_ref="oval:org.mitre.oval:tst:127074"/>
          <criterion comment="net-snmp-devel is earlier than 0:5.3.2.2-22.0.2.el5_10.1" test_ref="oval:org.mitre.oval:tst:127658"/>
          <criterion comment="net-snmp-libs is earlier than 0:5.3.2.2-22.0.2.el5_10.1" test_ref="oval:org.mitre.oval:tst:127128"/>
          <criterion comment="net-snmp-perl is earlier than 0:5.3.2.2-22.0.2.el5_10.1" test_ref="oval:org.mitre.oval:tst:127735"/>
          <criterion comment="net-snmp-utils is earlier than 0:5.3.2.2-22.0.2.el5_10.1" test_ref="oval:org.mitre.oval:tst:127706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27077" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1361 -- xulrunner security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1361.html" ref_id="ELSA-2012-1361"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4193" ref_id="CVE-2012-4193"/>
        <description>[10.0.8-2.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.8-2]
- Added patches from 10.0.9 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:39.164-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:07.094-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:45.893-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:59:45.506-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:59:45.506-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130651"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131083"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130591"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130576"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27075" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1014 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1014.html" ref_id="ELSA-2013-1014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1500" ref_id="CVE-2013-1500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1571" ref_id="CVE-2013-1571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2407" ref_id="CVE-2013-2407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2412" ref_id="CVE-2013-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2443" ref_id="CVE-2013-2443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2444" ref_id="CVE-2013-2444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2445" ref_id="CVE-2013-2445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2446" ref_id="CVE-2013-2446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2447" ref_id="CVE-2013-2447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2448" ref_id="CVE-2013-2448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2450" ref_id="CVE-2013-2450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2452" ref_id="CVE-2013-2452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2453" ref_id="CVE-2013-2453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2455" ref_id="CVE-2013-2455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2456" ref_id="CVE-2013-2456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2457" ref_id="CVE-2013-2457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2459" ref_id="CVE-2013-2459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2461" ref_id="CVE-2013-2461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2463" ref_id="CVE-2013-2463"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2465" ref_id="CVE-2013-2465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2469" ref_id="CVE-2013-2469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2470" ref_id="CVE-2013-2470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2471" ref_id="CVE-2013-2471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2472" ref_id="CVE-2013-2472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2473" ref_id="CVE-2013-2473"/>
        <description>[1:1.6.0.0-1.62.1.11.11.90]
- updated to icedtea6-1.11.11.90.tar.gz
- removed upstreamed patch9 jaxp-backport-factoryfinder.patch
- removed upstreamed patch10 fixToFontSecurityFix.patch.
- modified patch3, java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#973129</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:33.512-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:03.715-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:45.043-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:40:57.622-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:40:57.622-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129190"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129361"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129329"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129430"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129194"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129322"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129300"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129198"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129439"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27071" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2041 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2041.html" ref_id="ELSA-2012-2041"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.32-300.38.1]

- [net/sfc] limit number of segments per skb on tx (Maxim Uvarov) [Orabug:

  14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:54.068-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:02.590-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:44.464-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130810 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:26.477-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:05.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130626"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130810"/>
            <criterion comment="ofa-2.6.32-300.38.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130649"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130329"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130923"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130893"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130836"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130817"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130035"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130906"/>
            <criterion comment="ofa-2.6.32-300.38.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130921"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130783"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130957"/>
            <criterion comment="ofa-2.6.32-300.38.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130980"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130502"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130068"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130755"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130625"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130844"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130846"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131000"/>
            <criterion comment="ofa-2.6.32-300.38.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131003"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27067" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2040 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2040.html" ref_id="ELSA-2012-2040"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.39-200.34.1]

- [net/sfc] limit number of segments per skb on tx (Maxim Uvarov) [Orabug:

  14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:44.052-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:00.190-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:44.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130991"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130847"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:131054"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130619"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130972"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:131063"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130641"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130897"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130199"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130793"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130808"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130860"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27065" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1143-1 -- kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1143-1.html" ref_id="ELSA-2014-1143-1"/>
        <description>kernel
[2.6.18-371.12.1.0.1.el5]
- ocfs2: dlm: fix recovery hung (Junxiao Bi) [orabug 13956772]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 
14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 
14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 
14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 
13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 
14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong 
Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus 
(Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, 
Chris Mason)
   [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 
12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) 
[orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) 
[orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
   (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf 
(John Sobecki)
   [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
   hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
   NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 
9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
   [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
   [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
   Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) 
[orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) 
[orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:31.829-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:53.345-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:40.469-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124562"/>
          <criterion comment="kernel-PAE RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124247"/>
          <criterion comment="kernel-PAE-devel RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124922"/>
          <criterion comment="kernel-debug RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124462"/>
          <criterion comment="kernel-debug-devel RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124899"/>
          <criterion comment="kernel-devel RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124597"/>
          <criterion comment="kernel-doc RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124630"/>
          <criterion comment="kernel-headers RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124661"/>
          <criterion comment="kernel-xen RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124858"/>
          <criterion comment="kernel-xen-devel RPM is earlier than 0:2.6.18-371.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:124684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27060" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0920 -- httpd security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0920.html" ref_id="ELSA-2014-0920"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0118" ref_id="CVE-2014-0118"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0226" ref_id="CVE-2014-0226"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0231" ref_id="CVE-2014-0231"/>
        <description>[2.2.15-31.0.1.el6_5]
- replace index.html with Oracle's index page oracle_index.html
- update vstring in specfile

[2.2.15-31]
- mod_cgid: add security fix for CVE-2014-0231
- mod_deflate: add security fix for CVE-2014-0118
- mod_status: add security fix for CVE-2014-0226</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:14.544-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:59.600-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.933-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35269 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:43.351-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:30.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127237"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127077"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126724"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126959"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127165"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127233"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127288"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126977"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127107"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27059" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0807 -- hypervkvpd security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>hypervkvpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0807.html" ref_id="ELSA-2013-0807"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5532" ref_id="CVE-2012-5532"/>
        <description>[0-0.7.0.1.el5_9.3]
- Add support for oracle os

[0-0.7.3]
- Fix for one more file descriptor leak (rhbz#953502)

[0-0.7.2]
- Validate Netlink source address (CVE-2012-5532) (rhbz#953560)

[0-0.7.1]
- Fix for file descriptor leak (rhbz#953502)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:41.531-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:59.357-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.816-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:53:34.328-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:53:34.328-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="hypervkvpd is earlier than 0:0-0.7.0.1.el5_9.3" test_ref="oval:org.mitre.oval:tst:129555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27058" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1307 -- nss security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1307.html" ref_id="ELSA-2014-1307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1568" ref_id="CVE-2014-1568"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One)
input from certain RSA signatures. A remote attacker could use this flaw to
forge RSA certificates by providing a specially crafted signature to an
application using NSS. (CVE-2014-1568)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Antoine Delignat-Lavaud and Intel Product Security
Incident Response Team as the original reporters.

All NSS users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, applications using NSS must be restarted for this update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:25.755-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:52.544-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:38.059-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124938"/>
            <criterion comment="nss-devel RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:123989"/>
            <criterion comment="nss-pkcs11-devel RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124894"/>
            <criterion comment="nss-softokn RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124420"/>
            <criterion comment="nss-softokn-devel RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124946"/>
            <criterion comment="nss-softokn-freebl RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124472"/>
            <criterion comment="nss-softokn-freebl-devel RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124947"/>
            <criterion comment="nss-sysinit RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124029"/>
            <criterion comment="nss-tools RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124933"/>
            <criterion comment="nss-util RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124771"/>
            <criterion comment="nss-util-devel RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124963"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:125010"/>
            <criterion comment="nss-devel RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:124167"/>
            <criterion comment="nss-pkcs11-devel RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:124494"/>
            <criterion comment="nss-tools RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:124690"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124964"/>
            <criterion comment="nss-devel RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:125008"/>
            <criterion comment="nss-pkcs11-devel RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:125003"/>
            <criterion comment="nss-softokn RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:124461"/>
            <criterion comment="nss-softokn-devel RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:124965"/>
            <criterion comment="nss-softokn-freebl RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:125025"/>
            <criterion comment="nss-softokn-freebl-devel RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:124638"/>
            <criterion comment="nss-sysinit RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:125018"/>
            <criterion comment="nss-tools RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124086"/>
            <criterion comment="nss-util RPM is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:124471"/>
            <criterion comment="nss-util-devel RPM is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:124323"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27057" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1653 -- openssl security update</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
          <product>openssl-devel</product>
          <product>openssl-perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1653.html" ref_id="ELSA-2014-1653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566" ref_id="CVE-2014-3566"/>
        <description>[0.9.8e-31]
- add support for fallback SCSV to partially mitigate CVE-2014-3566
  (padding attack on SSL3)

[0.9.8e-30]
- fix CVE-2014-0221 - recursion in DTLS code leading to DoS
- fix CVE-2014-3505 - doublefree in DTLS packet processing
- fix CVE-2014-3506 - avoid memory exhaustion in DTLS
- fix CVE-2014-3508 - fix OID handling to avoid information leak
- fix CVE-2014-3510 - fix DoS in anonymous (EC)DH handling in DTLS

[0.9.8e-29]
- fix for CVE-2014-0224 - SSL/TLS MITM vulnerability

[0.9.8e-28]
- replace expired GlobalSign Root CA certificate in ca-bundle.crt</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:20:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:15.778-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27057 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:37.867-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27057 - Updated CVE references." date="2014-12-05T19:07:00.194-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-12-22T04:00:07.543-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:0.9.8e-31.el5_11" test_ref="oval:org.mitre.oval:tst:126221"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-31.el5_11" test_ref="oval:org.mitre.oval:tst:126206"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-31.el5_11" test_ref="oval:org.mitre.oval:tst:126163"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27051" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-0168-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0168-1.html" ref_id="ELSA-2013-0168-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1568" ref_id="CVE-2012-1568"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4444" ref_id="CVE-2012-4444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5515" ref_id="CVE-2012-5515"/>
        <description>kernel
[2.6.18-348.1.1.0.1]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:33.329-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:57.237-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.385-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35697 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:28.750-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:04.974-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130350"/>
          <criterion comment="ocfs2-2.6.18-348.1.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129611"/>
          <criterion comment="oracleasm-2.6.18-348.1.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129717"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130500"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130252"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130573"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130567"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130402"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130332"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130557"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130563"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.1.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130326"/>
          <criterion comment="ocfs2-2.6.18-348.1.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130546"/>
          <criterion comment="ocfs2-2.6.18-348.1.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130343"/>
          <criterion comment="ocfs2-2.6.18-348.1.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130236"/>
          <criterion comment="oracleasm-2.6.18-348.1.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130127"/>
          <criterion comment="oracleasm-2.6.18-348.1.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129968"/>
          <criterion comment="oracleasm-2.6.18-348.1.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27050" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1166 -- jakarta-commons-httpclient security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1166.html" ref_id="ELSA-2014-1166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3577" ref_id="CVE-2014-3577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6153" ref_id="CVE-2012-6153"/>
        <description>Jakarta Commons HTTPClient implements the client side of HTTP standards.

It was discovered that the HTTPClient incorrectly extracted host name from
an X.509 certificate subject&amp;#39;s Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3577)

For additional information on this flaw, refer to the Knowledgebase
article in the References section.

All jakarta-commons-httpclient users are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:24.738-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:52.348-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:37.137-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124625 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:25.775-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:52.659-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124590"/>
            <criterion comment="jakarta-commons-httpclient-demo RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124928"/>
            <criterion comment="jakarta-commons-httpclient-javadoc RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124812"/>
            <criterion comment="jakarta-commons-httpclient-manual RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124349"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124152"/>
            <criterion comment="jakarta-commons-httpclient-demo RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124670"/>
            <criterion comment="jakarta-commons-httpclient-javadoc RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124625"/>
            <criterion comment="jakarta-commons-httpclient-manual RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124620"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124923"/>
            <criterion comment="jakarta-commons-httpclient-demo RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124671"/>
            <criterion comment="jakarta-commons-httpclient-javadoc RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124645"/>
            <criterion comment="jakarta-commons-httpclient-manual RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124235"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27047" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2512 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2512.html" ref_id="ELSA-2013-2512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" ref_id="CVE-2013-0268"/>
        <description><![CDATA[kernel-uek
[2.6.32-300.39.5uek]
- x86/msr: Add capabilities check (Alan Cox) [Orabug: 16481233] {CVE-2013-0268}

ofa-2.6.32-300.39.5.el6uek
mlnx_en-2.6.32-300.39.5.el6uek
* Mon Dec 12 2011 Guru Anbalagane <guru.anbalagane@oracle.com>
- version 1.5.7-0.1

* Tue Nov 01 2011 Joe Jin <joe.jin@oracle.com>
- 1.5.7 for UEK kernel.

* Mon Sep 08 2008 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Added nfsrdma support

* Wed Aug 13 2008 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Added mlx4_en support

* Tue Aug 21 2007 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Added %build
LANG=C
export LANG
unset DISPLAY
 macro

* Sun Jan 28 2007 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Created spec file for kernel-ib]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:02.738-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:55.767-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.212-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128964 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:27.756-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:04.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129927"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128964"/>
            <criterion comment="ofa-2.6.32-300.39.5.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128968"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129657"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129540"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129603"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129585"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129850"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129001"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129982"/>
            <criterion comment="ofa-2.6.32-300.39.5.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129662"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129447"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129901"/>
            <criterion comment="ofa-2.6.32-300.39.5.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129834"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129854"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129696"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129557"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129961"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129760"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129951"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129997"/>
            <criterion comment="ofa-2.6.32-300.39.5.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129059"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27045" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0866 -- samba and samba3x security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0866.html" ref_id="ELSA-2014-0866"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0244" ref_id="CVE-2014-0244"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3493" ref_id="CVE-2014-3493"/>
        <description>[3.6.9-169]

- resolves: #1105499 - CVE-2014-0244: DoS in nmbd.

- resolves: #1108840 - CVE-2014-3493: DoS in smbd with unicode path names.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:32.048-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:55.326-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:42.993-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127425"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127395"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:126535"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127110"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127499"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127492"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127452"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127231"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127469"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127344"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127433"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127477"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127438"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127404"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127414"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127352"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:126955"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127271"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127279"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:126901"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27043" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3022 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3022.html" ref_id="ELSA-2014-3022"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0077" ref_id="CVE-2014-0077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <description>[2.6.39-400.214.6]
- aacraid: missing capable() check in compat ioctl (Dan Carpenter)  [Orabug: 18721962]  {CVE-2013-6383}
- vhost: fix total length when packets are too short (Michael S. Tsirkin)  [Orabug: 18721977]  {CVE-2014-0077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:29.020-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:54.895-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:42.755-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127466"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127559"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127314"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127663"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127467"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127688"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127091"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127530"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127417"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127661"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127612"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:126696"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27042" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3042 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3042.html" ref_id="ELSA-2014-3042"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6378" ref_id="CVE-2013-6378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1874" ref_id="CVE-2014-1874"/>
        <description>[2.6.39-400.215.3]
- SELinux: Fix kernel BUG on empty security contexts. (Stephen Smalley)  [Orabug: 19028380]  {CVE-2014-1874}
- floppy: don't write kernel-only members to FDRAWCMD ioctl output (Matthew Daley)  [Orabug: 19028444]  {CVE-2014-1738}
- floppy: ignore kernel-only members in FDRAWCMD ioctl input (Matthew Daley)  [Orabug: 19028438]  {CVE-2014-1737}
- libertas: potential oops in debugfs (Dan Carpenter)  [Orabug: 19028416]  {CVE-2013-6378}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:19.201-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:54.338-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:42.505-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127362"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127276"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127372"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:126585"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127429"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127575"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127476"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:126619"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127495"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127526"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127413"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27040" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1505 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1505.html" ref_id="ELSA-2013-1505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3829" ref_id="CVE-2013-3829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4002" ref_id="CVE-2013-4002"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5772" ref_id="CVE-2013-5772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5774" ref_id="CVE-2013-5774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5778" ref_id="CVE-2013-5778"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5780" ref_id="CVE-2013-5780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5782" ref_id="CVE-2013-5782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5783" ref_id="CVE-2013-5783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5784" ref_id="CVE-2013-5784"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5790" ref_id="CVE-2013-5790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5802" ref_id="CVE-2013-5802"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5803" ref_id="CVE-2013-5803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5804" ref_id="CVE-2013-5804"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5809" ref_id="CVE-2013-5809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5814" ref_id="CVE-2013-5814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5817" ref_id="CVE-2013-5817"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5820" ref_id="CVE-2013-5820"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5823" ref_id="CVE-2013-5823"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5825" ref_id="CVE-2013-5825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5829" ref_id="CVE-2013-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5830" ref_id="CVE-2013-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5840" ref_id="CVE-2013-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5842" ref_id="CVE-2013-5842"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5849" ref_id="CVE-2013-5849"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5850" ref_id="CVE-2013-5850"/>
        <description>[1:1.6.0.0-1.68.1.11.14]
- updated to icedtea6-1.11.14.tar.gz
- added and applied 1.11.14-fixes.patch, patch10 to fix build issues
- adapted patch8 java-1.6.0-openjdk-timezone-id.patch
- Resolves: rhbz#1017618

[1:1.6.0.1-1.67.1.13.0]
- reverted previous update
- Resolves: rhbz#1017618

[1:1.6.0.1-1.66.1.13.0]
- updated to icedtea 1.13
- updated to openjdk-6-src-b28-04_oct_2013
- added --disable-lcms2 configure switch to fix tck
- removed upstreamed patch7,java-1.6.0-openjdk-jstack.patch
- added patch7 1.13_fixes.patch to fix 1.13 build issues
- adapted patch0 java-1.6.0-openjdk-optflags.patch
- adapted patch3 java-1.6.0-openjdk-java-access-bridge-security.patch
- adapted patch8 java-1.6.0-openjdk-timezone-id.patch
- removed useless runtests parts
- included also java.security.old files
- Resolves: rhbz#1017618</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:10.592-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:51.142-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:41.684-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:11:47.057-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:11:47.057-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128586"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128370"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128122"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128649"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127811"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128800"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128678"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:127887"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128270"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128515"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27039" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1115 -- bind97 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1115.html" ref_id="ELSA-2013-1115"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4854" ref_id="CVE-2013-4854"/>
        <description>[32:9.7.0-17.P2.2]
- fix for CVE-2013-4854</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:40.963-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:50.874-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:41.445-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:15:01.900-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:15:01.900-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 0:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:128486"/>
          <criterion comment="bind97-chroot is earlier than 0:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:128974"/>
          <criterion comment="bind97-devel is earlier than 0:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:129276"/>
          <criterion comment="bind97-libs is earlier than 0:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:129246"/>
          <criterion comment="bind97-utils is earlier than 0:9.7.0-17.P2.el5_9.2" test_ref="oval:org.mitre.oval:tst:129233"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27026" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0696 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0696.html" ref_id="ELSA-2013-0696"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0796" ref_id="CVE-2013-0796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0800" ref_id="CVE-2013-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0795" ref_id="CVE-2013-0795"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0788" ref_id="CVE-2013-0788"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0793" ref_id="CVE-2013-0793"/>
        <description>firefox
[17.0.5-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.5-1]
- Update to 17.0.5 ESR

xulrunner
[17.0.5-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.5-1]
- Update to 17.0.5 ESR

[17.0.3-3]
- Added fix for rhbz#916180 - Wrong library directory reference
  in /usr/bin/xulrunner</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:04.455-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:45.208-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:39.883-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:58:39.764-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:58:39.764-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129861"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129860"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129853"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129660"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129720"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27020" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1474 -- qspice security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>qspice</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1474.html" ref_id="ELSA-2013-1474"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4282" ref_id="CVE-2013-4282"/>
        <description>[0.3.0-56.1]
- Fix spice-server crash when client sends a password which is too long
  Resolves: CVE-2013-4282

[0.3.0-56.el5]
- Fix unsafe accesses
  + spice: drop libpng from windows components (537849)
  + libspice: fix unsafe guest data accessing
Resolves: #568720
  + fix unsafe free() call.
Resolves: #568724
  + spice server: fix unsafe cursor items handling.
Resolves: #568720

[0.3.0-55.el5]
- spice: clear client palette caches on migration
Resolves: #599496</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:58.634-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:43.600-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:39.029-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:10:32.609-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:10:32.609-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qspice is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:128720"/>
          <criterion comment="qspice-libs is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:128776"/>
          <criterion comment="qspice-libs-devel is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:128699"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27015" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0311 -- php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0311.html" ref_id="ELSA-2014-0311"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689" ref_id="CVE-2009-0689"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7243" ref_id="CVE-2006-7243"/>
        <description>[5.1.6-44]
- add security fixes for CVE-2006-7243, CVE-2009-0689</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:40.125-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:42.928-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:38.556-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:27:31.165-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:27:31.165-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127040"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127903"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127826"/>
          <criterion comment="php-common is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127556"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127990"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127813"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127561"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127668"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127478"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:128012"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127849"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:128034"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127941"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127978"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127935"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127681"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127439"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127873"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:127914"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27012" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0594 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0594.html" ref_id="ELSA-2014-0594"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3466" ref_id="CVE-2014-3466"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3467" ref_id="CVE-2014-3467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3468" ref_id="CVE-2014-3468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469" ref_id="CVE-2014-3469"/>
        <description>[1.4.1-16]
- added missing check for null pointer (#1102355)

[1.4.1-15]
- fix session ID length check and null pointer dereference (#1102355)
- fix minitasn1 issues (#1102355)
- Renamed gnutls-1.4.1-cve-2014-5138.patch to cve-2009-5138.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:12.378-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:42.241-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:38.255-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:52:09.196-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:52:09.196-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:127297"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:127046"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:127455"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27009" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1778 -- gimp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1778.html" ref_id="ELSA-2013-1778"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5576" ref_id="CVE-2012-5576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1913" ref_id="CVE-2013-1913"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1978" ref_id="CVE-2013-1978"/>
        <description>[2:2.6.9-6]
- fix overflow in XWD loader (CVE-2013-1913, CVE-2013-1978)

[2:2.6.9-5]
- fix overflow in XWD loader (#879302)

[2:2.6.9-5]
- fix overflow in GIF loader (#847303)

[2:2.6.9-5]
- fix overflows in GIF, CEL loaders (#727800, #839020)

[2:2.6.9-4.1]
- fix various overflows (#666793, #703403, #703405, #703407, #704512)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:31.699-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:41.808-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:37.952-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:03:56.534-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:03:56.534-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gimp is earlier than 0:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:128321"/>
            <criterion comment="gimp-devel is earlier than 0:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:127836"/>
            <criterion comment="gimp-libs is earlier than 0:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:128353"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gimp is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128264"/>
            <criterion comment="gimp-devel is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128414"/>
            <criterion comment="gimp-devel-tools is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128422"/>
            <criterion comment="gimp-help-browser is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128135"/>
            <criterion comment="gimp-libs is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:127490"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27006" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1144 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1144.html" ref_id="ELSA-2014-1144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1562" ref_id="CVE-2014-1562"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1567" ref_id="CVE-2014-1567"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1562, CVE-2014-1567)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jan de Mooij as the original reporter of
CVE-2014-1562, and regenrecht as the original reporter of CVE-2014-1567.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.8.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.8.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:17.736-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:51.325-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:28.484-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox RPM is earlier than 0:24.8.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124258"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox RPM is earlier than 0:24.8.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124836"/>
            <criterion comment="xulrunner RPM is earlier than 0:24.8.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124875"/>
            <criterion comment="xulrunner-devel RPM is earlier than 0:24.8.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124822"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox RPM is earlier than 0:24.8.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124729"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27000" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0581 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0581.html" ref_id="ELSA-2013-0581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0338" ref_id="CVE-2013-0338"/>
        <description>[2.7.6-12.0.1.el6_4.1]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:49.799-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:40.421-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:37.450-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:38:20.214-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:38:20.214-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130269"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130280"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130286"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130256"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130142"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130193"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26999" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1194 -- conga security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1194.html" ref_id="ELSA-2014-1194"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5485" ref_id="CVE-2012-5485"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5486" ref_id="CVE-2012-5486"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5488" ref_id="CVE-2012-5488"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5497" ref_id="CVE-2012-5497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5498" ref_id="CVE-2012-5498"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5499" ref_id="CVE-2012-5499"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5500" ref_id="CVE-2012-5500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6496" ref_id="CVE-2013-6496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3521" ref_id="CVE-2014-3521"/>
        <description>The Conga project is a management system for remote workstations.
It consists of luci, which is a secure web-based front end, and ricci,
which is a secure daemon that dispatches incoming messages to underlying
management modules.

It was discovered that Plone, included as a part of luci, did not properly
protect the administrator interface (control panel). A remote attacker
could use this flaw to inject a specially crafted Python statement or
script into Plone&amp;#39;s restricted Python sandbox that, when the administrator
interface was accessed, would be executed with the privileges of that
administrator user. (CVE-2012-5485)

It was discovered that Plone, included as a part of luci, did not properly
sanitize HTTP headers provided within certain URL requests. A remote
attacker could use a specially crafted URL that, when processed, would
cause the injected HTTP headers to be returned as a part of the Plone HTTP
response, potentially allowing the attacker to perform other more advanced
attacks. (CVE-2012-5486)

Multiple information leak flaws were found in the way conga processed luci
site extension-related URL requests. A remote, unauthenticated attacker
could issue a specially crafted HTTP request that, when processed, would
result in unauthorized information disclosure. (CVE-2013-6496)

It was discovered that various components in the luci site
extension-related URLs were not properly restricted to administrative
users. A remote, authenticated attacker could escalate their privileges to
perform certain actions that should be restricted to administrative users,
such as adding users and systems, and viewing log data. (CVE-2014-3521)

It was discovered that Plone, included as a part of luci, did not properly
protect the privilege of running RestrictedPython scripts. A remote
attacker could use a specially crafted URL that, when processed, would
allow the attacker to submit and perform expensive computations or, in
conjunction with other attacks, be able to access or alter privileged
information. (CVE-2012-5488)

It was discovered that Plone, included as a part of luci, did not properly
enforce permissions checks on the membership database. A remote attacker
could use a specially crafted URL that, when processed, could allow the
attacker to enumerate user account names. (CVE-2012-5497)

It was discovered that Plone, included as a part of luci, did not properly
handle the processing of requests for certain collections. A remote
attacker could use a specially crafted URL that, when processed, would lead
to excessive I/O and/or cache resource consumption. (CVE-2012-5498)

It was discovered that Plone, included as a part of luci, did not properly
handle the processing of very large values passed to an internal utility
function. A remote attacker could use a specially crafted URL that, when
processed, would lead to excessive memory consumption. (CVE-2012-5499)

It was discovered that Plone, included as a part of luci, allowed a remote
anonymous user to change titles of content items due to improper
permissions checks. (CVE-2012-5500)

The CVE-2014-3521 issue was discovered by Radek Steiger of Red Hat, and the
CVE-2013-6496 issue was discovered by Jan Pokorny of Red Hat.

In addition, these updated conga packages include several bug fixes.
Space precludes documenting all of these changes in this advisory.
Users are directed to the Red Hat Enterprise Linux 5.11 Technical Notes,
linked to in the References section, for information on the most
significant of these changes

All conga users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the luci and ricci services will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:31.133-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:50.546-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:26.461-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="luci RPM is earlier than 0:0.12.2-81.0.2.el5" test_ref="oval:org.mitre.oval:tst:124551"/>
          <criterion comment="ricci RPM is earlier than 0:0.12.2-81.0.2.el5" test_ref="oval:org.mitre.oval:tst:124215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26995" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0890 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0890.html" ref_id="ELSA-2014-0890"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2483" ref_id="CVE-2014-2483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2490" ref_id="CVE-2014-2490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4209" ref_id="CVE-2014-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4216" ref_id="CVE-2014-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4218" ref_id="CVE-2014-4218"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4219" ref_id="CVE-2014-4219"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4221" ref_id="CVE-2014-4221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4223" ref_id="CVE-2014-4223"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4244" ref_id="CVE-2014-4244"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4252" ref_id="CVE-2014-4252"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4262" ref_id="CVE-2014-4262"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4263" ref_id="CVE-2014-4263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4266" ref_id="CVE-2014-4266"/>
        <description>[1.7.0.65-2.5.1.2.0.1.el5_10]
- Add oracle-enterprise.patch
- Fix DISTRO_NAME to 'Enterprise Linux'

[1.7.0.65-2.5.1.2]
- added and applied fix for samrtcard io patch405, pr1864_smartcardIO.patch
- Resolves: rhbz#1115872

[1.7.0.65-2.5.1.1.el5]
- updated to security patched icedtea7-forest 2.5.1
- Resolves: rhbz#1115872

[1.7.0.60-2.5.0.1.el5]
- update to icedtea7-forest 2.5.0 (rh1114937)
- Resolves: rhbz#1115872</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:26.545-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:37.988-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:36.855-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26995 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:44.111-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:29.448-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127428"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127381"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126697"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127337"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26989" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3019 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3019.html" ref_id="ELSA-2014-3019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2851" ref_id="CVE-2014-2851"/>
        <description>[2.6.39-400.214.5.el6uek]
- net: ipv4: current group_info should be put after using. (Wang, 
Xiaoming)  [Orabug: 18603524]  {CVE-2014-2851}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:02.934-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:50.279-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:24.517-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124673"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124537"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124835"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124585"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124828"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124457"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124847"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124779"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124410"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124528"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124548"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124546"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26986" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1090 -- nss and nspr security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1090.html" ref_id="ELSA-2012-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0441" ref_id="CVE-2012-0441"/>
        <description>nspr
[4.9.1-4]
- Resolves: rhbz#834219 - Fix postinstall scriptlet failures
- Fix %post and %postun lines per packaging guidelines
- Updated License: to MPLv2.0 per upstream

[4.9.1-3]
- Resolves: rhbz#834219 - Ensure nspr-config.in changes get applied

[4.9.1-2]
- Resolves: rhbz#834219 - restore top section of nspr-config-pc.patch
- Needed to prevent multilib regressions

nss
[3.13.5-4.0.1.el5_8  ]
- Update clean.gif in the tarball

[3.13.5-4]
- Related: rhbz#834219 - Fix ia64 / i386 multilib nss install failure
- Remove no longer needed %pre and %preun scriplets meant for nss updates from RHEL-5.0

[3.13.5-3]
- Resolves: rhbz#834219 - Fix the changes to the %post line
- Having multiple commands requires that /sbin/lconfig be the beginning of the scriptlet

[3.13.5-2]
- Resolves: rhbz#834219 - Fix multilib and scriptlet problems
- Fix %post and %postun lines per packaging guildelines
- Add %{?_isa} to tools Requires: per packaging guidelines
- Fix explicit-lib-dependency zlib error reported by rpmlint

[3.13.5-1]
- Resolves: rhbz#834219 - Update RHEL 5.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:34.744-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:37.001-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:36.167-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:17:45.214-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:17:45.214-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.9.1-4.el5_8" test_ref="oval:org.mitre.oval:tst:131359"/>
          <criterion comment="nss is earlier than 0:3.13.5-4.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130841"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.1-4.el5_8" test_ref="oval:org.mitre.oval:tst:131590"/>
          <criterion comment="nss-devel is earlier than 0:3.13.5-4.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131558"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.5-4.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131228"/>
          <criterion comment="nss-tools is earlier than 0:3.13.5-4.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26983" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2044 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2044.html" ref_id="ELSA-2012-2044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2133" ref_id="CVE-2012-2133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3400" ref_id="CVE-2012-3400"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3511" ref_id="CVE-2012-3511"/>
        <description>[2.6.32-300.39.1]

- hugepages: fix use after free bug in 'quota' handling [15842385] {CVE-2012-2133}

- mm: Hold a file reference in madvise_remove [15842884] {CVE-2012-3511}

- udf: Fortify loading of sparing table [15843730] {CVE-2012-3400}

- udf: Avoid run away loop when partition table length is corrupt [15843730] {CVE-2012-3400}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:56.033-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:36.337-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:35.833-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130939 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:25.221-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:03.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130676"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130934"/>
            <criterion comment="ofa-2.6.32-300.39.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130816"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130845"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130858"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130670"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130405"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130931"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130964"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130633"/>
            <criterion comment="ofa-2.6.32-300.39.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130952"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130628"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130939"/>
            <criterion comment="ofa-2.6.32-300.39.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130936"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130826"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130962"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130928"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130984"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130948"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130521"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130872"/>
            <criterion comment="ofa-2.6.32-300.39.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26980" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1266 -- bind97 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1266.html" ref_id="ELSA-2012-1266"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244" ref_id="CVE-2012-4244"/>
        <description>[32:9.7.0-10.P2.3]
- fix CVE-2012-4244</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:18.052-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:35.654-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:35.541-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:31:30.675-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:31:30.675-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 is earlier than 0:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:130915"/>
          <criterion comment="bind97-chroot is earlier than 0:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:130982"/>
          <criterion comment="bind97-devel is earlier than 0:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:131200"/>
          <criterion comment="bind97-libs is earlier than 0:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:131086"/>
          <criterion comment="bind97-utils is earlier than 0:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:131160"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26976" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1804 -- libjpeg security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libjpeg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1804.html" ref_id="ELSA-2013-1804"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6629" ref_id="CVE-2013-6629"/>
        <description>[6b-38]
- Add patch for CVE-2013-6629
- Resolves: #1031952</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:53.921-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:34.918-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:35.414-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:50:05.502-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:50:05.502-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libjpeg is earlier than 0:6b-38" test_ref="oval:org.mitre.oval:tst:128255"/>
          <criterion comment="libjpeg-devel is earlier than 0:6b-38" test_ref="oval:org.mitre.oval:tst:128308"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26970" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1244 -- bind97 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1244.html" ref_id="ELSA-2014-1244"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0591" ref_id="CVE-2014-0591"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4854" ref_id="CVE-2013-4854"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2266" ref_id="CVE-2013-2266"/>
        <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. It contains a DNS server (named), a resolver
library with routines for applications to use when interfacing with DNS,
and tools for verifying that the DNS server is operating correctly.
These packages contain version 9.7 of the BIND suite.

A denial of service flaw was found in the way BIND handled queries for
NSEC3-signed zones. A remote attacker could use this flaw against an
authoritative name server that served NCES3-signed zones by sending a
specially crafted query, which, when processed, would cause named to crash.
(CVE-2014-0591)

Note: The CVE-2014-0591 issue does not directly affect the version of
bind97 shipped in Red Hat Enterprise Linux 5. This issue is being addressed
however to assure it is not introduced in future builds of bind97 (possibly
built with a different compiler or C library optimization).

This update also fixes the following bug:

* Previously, the bind97 initscript did not check for the existence of the
ROOTDIR variable when shutting down the named daemon. As a consequence,
some parts of the file system that are mounted when using bind97 in a
chroot environment were unmounted on daemon shut down, even if bind97 was
not running in a chroot environment. With this update, the initscript has
been fixed to check for the existence of the ROOTDIR variable when
unmounting some parts of the file system on named daemon shut down. Now,
when shutting down bind97 that is not running in a chroot environment, no
parts of the file system are unmounted. (BZ#1059118)

All bind97 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:26.426-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:49.387-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:19.404-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124413 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:23.621-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:50.661-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind97 RPM is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:124413"/>
          <criterion comment="bind97-chroot RPM is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:124806"/>
          <criterion comment="bind97-devel RPM is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:124816"/>
          <criterion comment="bind97-libs RPM is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:124487"/>
          <criterion comment="bind97-utils RPM is earlier than 32:9.7.0-21.P2.el5" test_ref="oval:org.mitre.oval:tst:124849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26968" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2576 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2576.html" ref_id="ELSA-2013-2576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <description>[2.6.39-400.209.2]
- dm snapshot: fix data corruption (Mikulas Patocka) [Orabug: 17618492] {CVE-2013-4299}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:13.948-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:32.877-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:35.029-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128138"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128768"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128526"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128929"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128552"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:129070"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:129005"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:128847"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:129074"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:129003"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:128955"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:128958"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26958" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0330 -- samba and samba3x security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0330.html" ref_id="ELSA-2014-0330"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150" ref_id="CVE-2012-6150"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496" ref_id="CVE-2013-4496"/>
        <description>[3.6.9-168]
- resolves: #1073905 - Fix CVE-2012-6150.
- resolves: #1073905 - Fix CVE-2013-4496.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:16.212-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:30.900-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:33.937-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:15:23.399-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:15:23.399-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127584"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127740"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127574"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127788"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127969"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127298"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127745"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127948"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127734"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127717"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127738"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127605"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127684"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127987"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127773"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127966"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127709"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127842"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127944"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127901"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26957" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1768 -- php53 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1768.html" ref_id="ELSA-2014-1768"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3668" ref_id="CVE-2014-3668"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3669" ref_id="CVE-2014-3669"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3670" ref_id="CVE-2014-3670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3710" ref_id="CVE-2014-3710"/>
        <description>[5.3.3-26]
- fileinfo: fix out-of-bounds read in elf note headers. CVE-2014-3710

[5.3.3-25]
- xmlrpc: fix out-of-bounds read flaw in mkgmtime() CVE-2014-3668
- core: fix integer overflow in unserialize() CVE-2014-3669
- exif: fix heap corruption issue in exif_thumbnail() CVE-2014-3670</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:31.378-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:30.315-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:33.687-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php53 is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126554"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126618"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126211"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126485"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126645"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126622"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126517"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126505"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126570"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:125656"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126284"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126482"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126600"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126444"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126224"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126551"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126629"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126411"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:125659"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:125871"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-26.el5_11" test_ref="oval:org.mitre.oval:tst:126436"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26956" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0820 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0820.html" ref_id="ELSA-2013-0820"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0801" ref_id="CVE-2013-0801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1670" ref_id="CVE-2013-1670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1674" ref_id="CVE-2013-1674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1675" ref_id="CVE-2013-1675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1676" ref_id="CVE-2013-1676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1677" ref_id="CVE-2013-1677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1678" ref_id="CVE-2013-1678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1679" ref_id="CVE-2013-1679"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1680" ref_id="CVE-2013-1680"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1681" ref_id="CVE-2013-1681"/>
        <description>firefox
[17.0.6-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.6-1]
- Update to 17.0.6 ESR

[17.0.5-2]
- Updated XulRunner check

xulrunner
[17.0.6-2.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.6-2]
- Update to 17.0.6 ESR

[17.0.5-2]
- Updated nss and nspr versions</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:57.393-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:29.192-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:33.242-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:47:43.491-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:47:43.491-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129271"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128677"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128703"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129590"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129429"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129455"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26955" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1458 -- gnupg security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnupg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1458.html" ref_id="ELSA-2013-1458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4242" ref_id="CVE-2013-4242"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6085" ref_id="CVE-2012-6085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4351" ref_id="CVE-2013-4351"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4402" ref_id="CVE-2013-4402"/>
        <description>[1.4.5-18]
- fix CVE-2013-4351 gpg treats no-usage-permitted keys as all-usages-permitted

[1.4.5-17]
- fix CVE-2012-6085 GnuPG: read_block() corrupt key input validation
- fix CVE-2013-4242 GnuPG susceptible to Yarom/Falkner side-channel attack
- fix CVE-2013-4402 GnuPG: infinite recursion in the compressed packet parser

[1.4.5-15]
- fix error when decrypting certain files (#510500)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:12.187-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:28.687-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:33.029-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:37:31.180-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:37:31.180-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="gnupg is earlier than 0:1.4.5-18.el5_10" test_ref="oval:org.mitre.oval:tst:128655"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26954" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1053 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1053.html" ref_id="ELSA-2014-1053"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221" ref_id="CVE-2014-0221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3505" ref_id="CVE-2014-3505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3506" ref_id="CVE-2014-3506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3508" ref_id="CVE-2014-3508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3510" ref_id="CVE-2014-3510"/>
        <description>[0.9.8e-27.4]
        - fix CVE-2014-0221 - recursion in DTLS code leading to DoS
        - fix CVE-2014-3505 - doublefree in DTLS packet processing
        - fix CVE-2014-3506 - avoid memory exhaustion in DTLS
        - fix CVE-2014-3508 - fix OID handling to avoid information leak
        - fix CVE-2014-3510 - fix DoS in anonymous (EC)DH handling in DTLS</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:17.136-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:28.022-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:32.732-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:0.9.8e-27.el5_10.4" test_ref="oval:org.mitre.oval:tst:126962"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-27.el5_10.4" test_ref="oval:org.mitre.oval:tst:126877"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-27.el5_10.4" test_ref="oval:org.mitre.oval:tst:126937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26940" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0926 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0926.html" ref_id="ELSA-2014-0926"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2678" ref_id="CVE-2014-2678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4021" ref_id="CVE-2014-4021"/>
        <description>kernel
[2.6.18-371.11.1]
- [fs] dcache: fix cleanup on warning in d_splice_alias (Denys Vlasenko) [1109720 1080606]
- [net] neigh: Make neigh_add_timer symmetrical to neigh_del_timer (Marcelo Ricardo Leitner) [1111195 1109888]
- [net] neigh: set NUD_INCOMPLETE when probing router reachability (Marcelo Ricardo Leitner) [1106354 1090806]
- [net] ipv6: router reachability probing (Marcelo Ricardo Leitner) [1106354 1090806]
- [net] ipv6: probe routes asynchronous in rt6_probe (Marcelo Ricardo Leitner) [1106354 1090806]
- [net] ndisc: Update neigh->updated with write lock (Marcelo Ricardo Leitner) [1106354 1090806]
- [net] ipv6: remove the unnecessary statement in find_match() (Marcelo Ricardo Leitner) [1106354 1090806]
- [net] ipv6: fix route selection if CONFIG_IPV6_ROUTER_PREF unset (Marcelo Ricardo Leitner) [1106354 1090806]
- [net] ipv6: Fix def route failover when CONFIG_IPV6_ROUTER_PREF=n (Marcelo Ricardo Leitner) [1106354 1090806]
- [net] ipv6: Prefer reachable nexthop only if the caller requests (Marcelo Ricardo Leitner) [1106354 1090806]
- [fs] ext4/jbd2: don't wait forever stale tid caused by wraparound (Eric Sandeen) [1097528 980268]
- [fs] ext4: Initialize fsync transaction ids in ext4_new_inode() (Eric Sandeen) [1097528 980268]
- [fs] jbd2: don't wake kjournald unnecessarily (Eric Sandeen) [1097528 980268]
- [fs] jbd2: fix fsync() tid wraparound bug (Eric Sandeen) [1097528 980268]
- [infiniband] rds: do not deref NULL dev in rds_iw_laddr_check() (Jacob Tanenbaum) [1093311 1093312] {CVE-2014-2678}
- [fs] nfs4: Add recovery for individual stateids - partial backport. (Dave Wysochanski) [1113468 867570]
- [fs] nfs4: Don't start state recovery in nfs4_close_done - clean backport. (Dave Wysochanski) [1113468 867570]
- [xen] page-alloc: scrub anonymous domain heap pages upon freeing (Vitaly Kuznetsov) [1103648 1103649] {CVE-2014-4021}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:31.303-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:24.386-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:31.848-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126763 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:30.925-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:03.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:126735"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:126831"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:126590"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:126810"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:127207"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:126912"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:127161"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:127220"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:126460"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:126691"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:127170"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.11.1.el5" test_ref="oval:org.mitre.oval:tst:126795"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127129"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:126620"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:126763"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:126371"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127205"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:126804"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26932" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0241 -- xen security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0241.html" ref_id="ELSA-2013-0241"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4544" ref_id="CVE-2012-4544"/>
        <description>[3.0.3-142.el5_9.1]
- libxc: move error checking next to the function which returned the error (rhbz 876997)
- libxc: builder: limit maximum size of   kernel/ramdisk (rhbz 876997)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:45.605-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:22.204-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:30.950-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:45:20.649-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:45:20.649-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xen is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:130415"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:130361"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:130399"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26923" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1293 -- bash security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1293.html" ref_id="ELSA-2014-1293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271" ref_id="CVE-2014-6271"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

A flaw was found in the way Bash evaluated certain specially crafted
environment variables. An attacker could use this flaw to override or
bypass environment restrictions to execute shell commands. Certain
services and applications allow remote unauthenticated attackers to
provide environment variables, allowing them to exploit this issue.
(CVE-2014-6271)

For additional information on the CVE-2014-6271 flaw, refer to the
Knowledgebase article at &lt;A HREF="https://access.redhat.com/articles/1200223">https://access.redhat.com/articles/1200223&lt;/A>

Red Hat would like to thank Stephane Chazelas for reporting this issue.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:22.256-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:47.720-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:10.564-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:124796"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:124935"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:124345"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:124949"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="bash RPM is earlier than 0:3.2-33.el5.1" test_ref="oval:org.mitre.oval:tst:124844"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26920" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0408 -- java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0408.html" ref_id="ELSA-2014-0408"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0429" ref_id="CVE-2014-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0446" ref_id="CVE-2014-0446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0451" ref_id="CVE-2014-0451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0452" ref_id="CVE-2014-0452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0453" ref_id="CVE-2014-0453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0456" ref_id="CVE-2014-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0457" ref_id="CVE-2014-0457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0458" ref_id="CVE-2014-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0460" ref_id="CVE-2014-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0461" ref_id="CVE-2014-0461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1876" ref_id="CVE-2014-1876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2397" ref_id="CVE-2014-2397"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2398" ref_id="CVE-2014-2398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2403" ref_id="CVE-2014-2403"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2412" ref_id="CVE-2014-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2414" ref_id="CVE-2014-2414"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2421" ref_id="CVE-2014-2421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2423" ref_id="CVE-2014-2423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2427" ref_id="CVE-2014-2427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

This update also fixes the following bug:

* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:07.505-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:46.736-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:08.356-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:40:03.441-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:40:03.441-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124680"/>
            <criterion comment="java-1.6.0-openjdk-demo RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124417"/>
            <criterion comment="java-1.6.0-openjdk-devel RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124293"/>
            <criterion comment="java-1.6.0-openjdk-javadoc RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:123890"/>
            <criterion comment="java-1.6.0-openjdk-src RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124815"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124871"/>
            <criterion comment="java-1.6.0-openjdk-demo RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124633"/>
            <criterion comment="java-1.6.0-openjdk-devel RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124683"/>
            <criterion comment="java-1.6.0-openjdk-javadoc RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124043"/>
            <criterion comment="java-1.6.0-openjdk-src RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124221"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26913" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2047 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2047.html" ref_id="ELSA-2012-2047"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2375" ref_id="CVE-2012-2375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4565" ref_id="CVE-2012-4565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5517" ref_id="CVE-2012-5517"/>
        <description>[2.6.39-300.17.3]
- mm/hotplug: correctly add new zone to all other nodes zone lists (Jiang Liu)
  [Orabug: 16020976 Bug-db: 14798] {CVE-2012-5517}
- Divide by zero in TCP congestion control Algorithm. (Jesper Dangaard Brouer)
  [Orabug: 16020656 Bug-db: 14798] {CVE-2012-4565}
- Fix length of buffer copied in __nfs4_get_acl_uncached (Sachin Prabhu) [Bug-
  db: 14798] {CVE-2012-2375}
- Avoid reading past buffer when calling GETACL (Sachin Prabhu) [Bug-db: 14798]
  {CVE-2012-2375}
- Avoid beyond bounds copy while caching ACL (Sachin Prabhu) [Bug-db: 14798]
  {CVE-2012-2375}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:34.704-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:15.109-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:30.162-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130778"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130809"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130713"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130716"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130168"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130586"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130707"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:129856"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130631"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130247"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130754"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130453"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26906" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1869 -- pixman security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1869.html" ref_id="ELSA-2013-1869"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6425" ref_id="CVE-2013-6425"/>
        <description>[0.26.2-5.1]
- Fix CVE 2013-6425</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:22.441-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:13.777-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.852-05:00">ACCEPTED</status_change>
            <modified comment="duplicate" date="2015-02-11T09:27:14.566-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T09:27:14.566-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:128219"/>
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:128278"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:127843"/>
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:127636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26901" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-0747-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0747-1.html" ref_id="ELSA-2013-0747-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6547" ref_id="CVE-2012-6547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" ref_id="CVE-2012-6542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6546" ref_id="CVE-2012-6546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1826" ref_id="CVE-2013-1826"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0216" ref_id="CVE-2013-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0231" ref_id="CVE-2013-0231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6537" ref_id="CVE-2012-6537"/>
        <description>kernel
[2.6.18-348.4.1.0.1]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:48.968-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:12.408-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.526-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35723 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:26.196-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:02.121-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129693"/>
          <criterion comment="ocfs2-2.6.18-348.4.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129755"/>
          <criterion comment="oracleasm-2.6.18-348.4.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129727"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129635"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129214"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129688"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129601"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129529"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129748"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129785"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129622"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.4.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129722"/>
          <criterion comment="ocfs2-2.6.18-348.4.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129519"/>
          <criterion comment="ocfs2-2.6.18-348.4.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129434"/>
          <criterion comment="ocfs2-2.6.18-348.4.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129012"/>
          <criterion comment="oracleasm-2.6.18-348.4.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128816"/>
          <criterion comment="oracleasm-2.6.18-348.4.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129058"/>
          <criterion comment="oracleasm-2.6.18-348.4.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129735"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26898" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1319 -- sssd security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1319.html" ref_id="ELSA-2013-1319"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0219" ref_id="CVE-2013-0219"/>
        <description>[1.5.1-70]

- Fix IPA provider performance issue when storing large host groups

- Resolves: rhbz#979047 - sssd_be goes to 99% CPU and causes significant

                          login delays when client is under load</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:54.858-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:11.090-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.390-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sssd is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:128643"/>
          <criterion comment="libipa_hbac is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:128988"/>
          <criterion comment="libipa_hbac-devel is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:128560"/>
          <criterion comment="libipa_hbac-python is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:128616"/>
          <criterion comment="sssd-client is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:128511"/>
          <criterion comment="sssd-tools is earlier than 0:1.5.1-70.el5" test_ref="oval:org.mitre.oval:tst:129079"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26897" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1861 -- nss security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nss-devel</product>
          <product>nss-pkcs11-devel</product>
          <product>nss-tools</product>
          <product>nss-sysinit</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1861.html" ref_id="ELSA-2013-1861"/>
        <description>[3.15.3-3.0.1.el6_5]
- Added nss-vendor.patch to change vendor

[3.15.3-3]
- Revoke trust in one mis-issued anssi certificate
- Resolves: Bug 1042685 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:49.804-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:10.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.260-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:13:23.170-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:13:23.170-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:128030"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:128248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:127577"/>
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:127863"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128064"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127925"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128115"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128266"/>
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128176"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26895" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2013 -- Unbreakable Enterprise kernel security  update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2013.html" ref_id="ELSA-2012-2013"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4086" ref_id="CVE-2011-4086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1601" ref_id="CVE-2012-1601"/>
        <description>[2.6.39-100.7.1.el6uek]
- KVM: Ensure all vcpus are consistent with in-kernel irqchip settings (Avi
  Kivity) [Bugdb: 13871] {CVE-2012-1601}
- jbd2: clear BH_Delay &amp; BH_Unwritten in journal_unmap_buffer (Eric Sandeen)
  [Bugdb: 13871] {CVE-2011-4086}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:07.428-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:10.358-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.007-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132132"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131536"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132267"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131961"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131589"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131825"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:131811"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132268"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:131991"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132216"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132258"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26892" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1148 -- squid security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1148.html" ref_id="ELSA-2014-1148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4115" ref_id="CVE-2013-4115"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3609" ref_id="CVE-2014-3609"/>
        <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A flaw was found in the way Squid handled malformed HTTP Range headers.
A remote attacker able to send HTTP requests to the Squid proxy could use
this flaw to crash Squid. (CVE-2014-3609)

A buffer overflow flaw was found in Squid&amp;#39;s DNS lookup module. A remote
attacker able to send HTTP requests to the Squid proxy could use this flaw
to crash Squid. (CVE-2013-4115)

Red Hat would like to thank the Squid project for reporting the
CVE-2014-3609 issue. Upstream acknowledges Matthew Daley as the original
reporter.

All Squid users are advised to upgrade to this updated package, which
contains backported patches to correct these issues. After installing this
update, the squid service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:27.830-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:45.654-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:04.981-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124639 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:45.883-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:29.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="squid RPM is earlier than 7:3.1.10-22.el6_5" test_ref="oval:org.mitre.oval:tst:124639"/>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="squid RPM is earlier than 7:2.6.STABLE21-7.el5_10" test_ref="oval:org.mitre.oval:tst:124741"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26887" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1210 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1210.html" ref_id="ELSA-2012-1210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1970" ref_id="CVE-2012-1970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1972" ref_id="CVE-2012-1972"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1973" ref_id="CVE-2012-1973"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1974" ref_id="CVE-2012-1974"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1975" ref_id="CVE-2012-1975"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1976" ref_id="CVE-2012-1976"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3956" ref_id="CVE-2012-3956"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3957" ref_id="CVE-2012-3957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3958" ref_id="CVE-2012-3958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3959" ref_id="CVE-2012-3959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3960" ref_id="CVE-2012-3960"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3961" ref_id="CVE-2012-3961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3962" ref_id="CVE-2012-3962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3963" ref_id="CVE-2012-3963"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3964" ref_id="CVE-2012-3964"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3966" ref_id="CVE-2012-3966"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3967" ref_id="CVE-2012-3967"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3968" ref_id="CVE-2012-3968"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3969" ref_id="CVE-2012-3969"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3970" ref_id="CVE-2012-3970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3972" ref_id="CVE-2012-3972"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3976" ref_id="CVE-2012-3976"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3978" ref_id="CVE-2012-3978"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3980" ref_id="CVE-2012-3980"/>
        <description>firefox
[10.0.7-1.0.1.el6_3]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.7-1]
- Update to 10.0.7 ESR

xulrunner
[10.0.7-1.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.7-1]
- Update to 10.0.7 ESR

[10.0.6-2]
- Added fix for rhbz#770276 - Firefox segfaults, should
  have a font dependency</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:22.924-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:06.121-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.931-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:03:10.370-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:03:10.370-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.7-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131040"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131282"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131235"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.7-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130992"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131356"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131336"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26876" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0305 -- samba security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0305.html" ref_id="ELSA-2014-0305"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213" ref_id="CVE-2013-0213"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214" ref_id="CVE-2013-0214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124" ref_id="CVE-2013-4124"/>
        <description>[3.0.33-3.40.el5]
- Security Release, fixes CVE-2013-0213 and CVE-2013-4124
- resolves: #1073350</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:23.691-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:04.079-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.172-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:22:49.961-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:22:49.961-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:127716"/>
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:127045"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:127970"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:127807"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:127977"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:128006"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26872" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1193 -- axis security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1193.html" ref_id="ELSA-2014-1193"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3596" ref_id="CVE-2014-3596"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5784" ref_id="CVE-2012-5784"/>
        <description>Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

It was discovered that Axis incorrectly extracted the host name from an
X.509 certificate subject&amp;#39;s Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3596)

For additional information on this flaw, refer to the Knowledgebase article
in the References section.

This issue was discovered by David Jorm and Arun Neelicattu of Red Hat
Product Security.

All axis users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Applications using Apache
Axis must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:19.849-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:44.643-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:02.274-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="axis RPM is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:124832"/>
            <criterion comment="axis-javadoc RPM is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:124581"/>
            <criterion comment="axis-manual RPM is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:124399"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="axis RPM is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:124956"/>
            <criterion comment="axis-javadoc RPM is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:124769"/>
            <criterion comment="axis-manual RPM is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:124877"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26871" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1362 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1362.html" ref_id="ELSA-2012-1362"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4193" ref_id="CVE-2012-4193"/>
        <description>[10.0.8-2.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.8-2]
- Added patches from 10.0.9 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:18.717-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:03.838-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.054-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:10:03.769-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:10:03.769-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131084"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26857" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1265 -- libxslt security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxslt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1265.html" ref_id="ELSA-2012-1265"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1202" ref_id="CVE-2011-1202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3970" ref_id="CVE-2011-3970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2825" ref_id="CVE-2012-2825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2870" ref_id="CVE-2012-2870"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2871" ref_id="CVE-2012-2871"/>
        <description>[1.1.26-2.0.2.el6_3.1]
- Increment release to avoid ULN conflict with previous release.

[1.1.26-2.0.1.el6_3.1]
- Added libxslt-oracle-enterprise.patch and replaced doc/redhat.gif in tarball

[1.1.26-2.el6_3.1]
- fixes CVE-2011-1202 CVE-2011-3970 CVE-2012-2825 CVE-2012-2871 CVE-2012-2870
- Fix direct pattern matching bug
- Fix popping of vars in xsltCompilerNodePop
- Fix bug 602515
- Fix generate-id() to not expose object addresses (CVE-2011-1202)
- Fix some case of pattern parsing errors (CVE-2011-3970)
- Fix a bug in selecting XSLT elements (CVE-2012-2825)
- Fix portability to upcoming libxml2-2.9.0
- Fix default template processing on namespace nodes (CVE-2012-2871)
- Cleanup of the pattern compilation code (CVE-2012-2870)
- Hardening of code checking node types in various entry point (CVE-2012-2870)
- Hardening of code checking node types in EXSLT (CVE-2012-2870)
- Fix system-property with unknown namespace
- Xsltproc should return an error code if xinclude fails
- Fix a dictionary string usage
- Avoid a heap use after free error</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:34.783-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:02.770-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:25.508-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:44:16.893-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:44:16.893-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxslt is earlier than 0:1.1.17-4.0.1.el5_8.3" test_ref="oval:org.mitre.oval:tst:130522"/>
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-4.0.1.el5_8.3" test_ref="oval:org.mitre.oval:tst:131116"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-4.0.1.el5_8.3" test_ref="oval:org.mitre.oval:tst:131087"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxslt is earlier than 0:1.1.26-2.0.2.el6_3.1" test_ref="oval:org.mitre.oval:tst:131174"/>
            <criterion comment="libxslt-devel is earlier than 0:1.1.26-2.0.2.el6_3.1" test_ref="oval:org.mitre.oval:tst:131115"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.26-2.0.2.el6_3.1" test_ref="oval:org.mitre.oval:tst:130266"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26856" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1255 -- krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1255.html" ref_id="ELSA-2014-1255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4345" ref_id="CVE-2014-4345"/>
        <description>Kerberos is an authentication system which allows clients and services to
authenticate to each other with the help of a trusted third party, a
Kerberos Key Distribution Center (KDC).

A buffer overflow was found in the KADM5 administration server (kadmind)
when it was used with an LDAP back end for the KDC database. A remote,
authenticated attacker could potentially use this flaw to execute arbitrary
code on the system running kadmind. (CVE-2014-4345)

All krb5 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the krb5kdc and kadmind daemons will be restarted
automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:26.172-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:42.305-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:00.082-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5-devel RPM is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:124838"/>
          <criterion comment="krb5-libs RPM is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:124676"/>
          <criterion comment="krb5-server RPM is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:124110"/>
          <criterion comment="krb5-server-ldap RPM is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:124955"/>
          <criterion comment="krb5-workstation RPM is earlier than 0:1.6.1-80.el5_11" test_ref="oval:org.mitre.oval:tst:124707"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26852" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1483 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1483.html" ref_id="ELSA-2012-1483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4201" ref_id="CVE-2012-4201"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4202" ref_id="CVE-2012-4202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4207" ref_id="CVE-2012-4207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4209" ref_id="CVE-2012-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4214" ref_id="CVE-2012-4214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4215" ref_id="CVE-2012-4215"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4216" ref_id="CVE-2012-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5829" ref_id="CVE-2012-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5830" ref_id="CVE-2012-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5833" ref_id="CVE-2012-5833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5835" ref_id="CVE-2012-5835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5839" ref_id="CVE-2012-5839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5840" ref_id="CVE-2012-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5841" ref_id="CVE-2012-5841"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5842" ref_id="CVE-2012-5842"/>
        <description>[10.0.11-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[10.0.11-1]
- Update to 10.0.11 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:54.478-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:01.091-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:24.620-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:31:51.728-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:31:51.728-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130679"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26844" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0433 -- kernel security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0433.html" ref_id="ELSA-2014-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6638" ref_id="CVE-2012-6638"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <description>kernel
[2.6.18-371.8.1]
- [virt] HID: memory corruption flaw drivers/usb/input/hid-core.c (Jacob Tanenbaum) [1032996 1032999] {CVE-2013-2888}
- [virt] HID: memory corruption flaw in drivers/hv/hid-core.c (Jacob Tanenbaum) [1032996 1032999] {CVE-2013-2888}
- [scsi] lpfc: Fix task management commands having a fixed timeout (Ewan Milne) [1073123 1061120]
- [net] tcp: drop SYN+FIN messages (Jiri Pirko) [1066057 1066058] {CVE-2012-6638}
- [fs] GFS2: Check if glock held in gfs2_readpage (Robert S Peterson) [1073953 1063434]
- [net] sunrpc: fix deadlock in task wakeup code (Jeff Layton) [1073731 998126]

[2.6.18-371.7.1]
- [s390x] af_iucv: Kernel panic during connect (IUCV transport) (Hendrik Brueckner) [1077045 1026388]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:43.319-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:59.380-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:24.011-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:37:52.774-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:37:52.774-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127742"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.8.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127408"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.8.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127235"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127653"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127669"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127487"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127068"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127346"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127741"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127317"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127674"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:127715"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.8.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127685"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.8.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127652"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.8.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:126914"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.8.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127319"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.8.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127498"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.8.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127375"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26825" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0407 -- java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0407.html" ref_id="ELSA-2014-0407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0429" ref_id="CVE-2014-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0446" ref_id="CVE-2014-0446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0451" ref_id="CVE-2014-0451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0452" ref_id="CVE-2014-0452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0453" ref_id="CVE-2014-0453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0454" ref_id="CVE-2014-0454"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0455" ref_id="CVE-2014-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0456" ref_id="CVE-2014-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0457" ref_id="CVE-2014-0457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0458" ref_id="CVE-2014-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0459" ref_id="CVE-2014-0459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0460" ref_id="CVE-2014-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0461" ref_id="CVE-2014-0461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1876" ref_id="CVE-2014-1876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2397" ref_id="CVE-2014-2397"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2398" ref_id="CVE-2014-2398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2402" ref_id="CVE-2014-2402"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2403" ref_id="CVE-2014-2403"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2412" ref_id="CVE-2014-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2413" ref_id="CVE-2014-2413"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2414" ref_id="CVE-2014-2414"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2421" ref_id="CVE-2014-2421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2423" ref_id="CVE-2014-2423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2427" ref_id="CVE-2014-2427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:05.284-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:38.912-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:57.243-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:36:24.277-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:36:24.277-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124559"/>
          <criterion comment="java-1.7.0-openjdk-demo RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124888"/>
          <criterion comment="java-1.7.0-openjdk-devel RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124523"/>
          <criterion comment="java-1.7.0-openjdk-javadoc RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124823"/>
          <criterion comment="java-1.7.0-openjdk-src RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124839"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26804" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1004 -- yum-updatesd security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>yum-updatesd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1004.html" ref_id="ELSA-2014-1004"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0022" ref_id="CVE-2014-0022"/>
        <description>[1:0.9-6]
        - updatesd: prevent installing unsigned packages.
        - Resolves: rhbz#1125185</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:25.447-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:56.374-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:22.992-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126886 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:26.035-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:50.037-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="yum-updatesd is earlier than 1:0.9-6.el5_10" test_ref="oval:org.mitre.oval:tst:126886"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26803" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0369 -- httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0369.html" ref_id="ELSA-2014-0369"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0098" ref_id="CVE-2014-0098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6438" ref_id="CVE-2013-6438"/>
        <description>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

It was found that the mod_dav module did not correctly strip leading white
space from certain elements in a parsed XML. In certain httpd
configurations that use the mod_dav module (for example when using the
mod_dav_svn module), a remote attacker could send a specially crafted DAV
request that would cause the httpd child process to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
&amp;quot;apache&amp;quot; user. (CVE-2013-6438)

A buffer over-read flaw was found in the httpd mod_log_config module.
In configurations where cookie logging is enabled (on Red Hat Enterprise
Linux it is disabled by default), a remote attacker could use this flaw to
crash the httpd child process via an HTTP request with a malformed cookie
header. (CVE-2014-0098)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:04.830-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:36.805-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:55.531-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:22:05.967-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:22:05.967-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd RPM is earlier than 0:2.2.3-85.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124775"/>
          <criterion comment="httpd-devel RPM is earlier than 0:2.2.3-85.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124489"/>
          <criterion comment="httpd-manual RPM is earlier than 0:2.2.3-85.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124803"/>
          <criterion comment="mod_ssl RPM is earlier than 0:2.2.3-85.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124641"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26800" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-0621-1 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0621-1.html" ref_id="ELSA-2013-0621-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" ref_id="CVE-2013-0268"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" ref_id="CVE-2013-0871"/>
        <description>kernel
[2.6.18-348.3.1.0.1]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:47.669-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:55.952-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:22.667-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130056 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:22.949-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:00.450-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129876"/>
          <criterion comment="ocfs2-2.6.18-348.3.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129864"/>
          <criterion comment="oracleasm-2.6.18-348.3.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129986"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130009"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130014"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129563"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130044"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129744"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129777"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130048"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129894"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:130013"/>
          <criterion comment="ocfs2-2.6.18-348.3.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130061"/>
          <criterion comment="ocfs2-2.6.18-348.3.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129709"/>
          <criterion comment="ocfs2-2.6.18-348.3.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:130055"/>
          <criterion comment="oracleasm-2.6.18-348.3.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129848"/>
          <criterion comment="oracleasm-2.6.18-348.3.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:130056"/>
          <criterion comment="oracleasm-2.6.18-348.3.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26796" version="6" class="patch">
      <metadata>
        <title>ELSA-2014-1633 -- java-1.7.0-openjdk security and bug fix update</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1633.html" ref_id="ELSA-2014-1633"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6457" ref_id="CVE-2014-6457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6502" ref_id="CVE-2014-6502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6504" ref_id="CVE-2014-6504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6506" ref_id="CVE-2014-6506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6511" ref_id="CVE-2014-6511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6512" ref_id="CVE-2014-6512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6517" ref_id="CVE-2014-6517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6519" ref_id="CVE-2014-6519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6531" ref_id="CVE-2014-6531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6558" ref_id="CVE-2014-6558"/>
        <description>[1:1.7.0.71-2.5.3.1.0.1.el5_11]
- Add oracle-enterprise.patch
- Fix DISTRO_NAME to 'Enterprise Linux'

[1:1.7.0.71-2.5.3.1]
- Bump to 2.5.3 with security updates.
- Remove obsolete patches which are now included upstream.
- Disable LCMS via environment variables rather than maintaining a patch.
- Resolves: rhbz#1148890</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:20:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:19.193-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26796 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:00:54.187-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:22.807-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126187 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:43.879-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:28.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126008"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126340"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126056"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126213"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126187"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26786" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0348 -- xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xalan-j2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0348.html" ref_id="ELSA-2014-0348"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0107" ref_id="CVE-2014-0107"/>
        <description>Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types.

It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features.
A remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses
Xalan-Java. (CVE-2014-0107)

All xalan-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:00.981-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:35.010-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:53.106-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:17:36.885-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:17:36.885-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xalan-j2 RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124565"/>
            <criterion comment="xalan-j2-demo RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124758"/>
            <criterion comment="xalan-j2-javadoc RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124416"/>
            <criterion comment="xalan-j2-manual RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124813"/>
            <criterion comment="xalan-j2-xsltc RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124545"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xalan-j2 RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124159"/>
            <criterion comment="xalan-j2-demo RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124669"/>
            <criterion comment="xalan-j2-javadoc RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124696"/>
            <criterion comment="xalan-j2-manual RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:123858"/>
            <criterion comment="xalan-j2-xsltc RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124519"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26760" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1172 -- procmail security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>procmail</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1172.html" ref_id="ELSA-2014-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3618" ref_id="CVE-2014-3618"/>
        <description>The procmail program is used for local mail delivery. In addition to just
delivering mail, procmail can be used for automatic filtering, presorting,
and other mail handling jobs.

A heap-based buffer overflow flaw was found in procmail&amp;#39;s formail utility.
A remote attacker could send an email with specially crafted headers that,
when processed by formail, could cause procmail to crash or, possibly,
execute arbitrary code as the user running formail. (CVE-2014-3618)

All procmail users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:22.759-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:32.237-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:49.663-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criterion comment="procmail RPM is earlier than 0:3.22-34.el7_0.1" test_ref="oval:org.mitre.oval:tst:124451"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="procmail RPM is earlier than 0:3.22-25.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:124717"/>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="procmail RPM is earlier than 0:3.22-17.1.2.0.1" test_ref="oval:org.mitre.oval:tst:124903"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26754" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1143 -- kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1143.html" ref_id="ELSA-2014-1143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" ref_id="CVE-2014-3917"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* An out-of-bounds memory access flaw was found in the Linux kernel&amp;#39;s
system call auditing implementation. On a system with existing audit rules
defined, a local, unprivileged user could use this flaw to leak kernel
memory to user space or, potentially, crash the system. (CVE-2014-3917,
Moderate)

This update also fixes the following bugs:

* A bug in the journaling code (jbd and jbd2) could, under very heavy
workload of fsync() operations, trigger a BUG_ON and result in a kernel
oops. Also, fdatasync() could fail to immediately write out changes in the
file size only. These problems have been resolved by backporting a series
of patches that fixed these problems in the respective code on Red Hat
Enterprise Linux 6. This update also improves performance of ext3 and ext4
file systems. (BZ#1116027)

* Due to a bug in the ext4 code, the fdatasync() system call did not force
the inode size change to be written to the disk if it was the only metadata
change in the file. This could result in the wrong inode size and possible
data loss if the system terminated unexpectedly. The code handling inode
updates has been fixed and fdatasync() now writes data to the disk as
expected in this situation. (BZ#1117665)

* A workaround to a DMA read problem in the tg3 driver was incorrectly
applied to the whole Broadcom 5719 and 5720 chipset family. This workaround
is valid only to the A0 revision of the 5719 chips and for other revisions
and chips causes occasional Tx timeouts. This update correctly applies the
aforementioned workaround only to the A0 revision of the 5719 chips.
(BZ#1121017)

* Due to a bug in the page writeback code, the system could become
unresponsive when being under memory pressure and heavy NFS load. This
update fixes the code responsible for handling of dirty pages, and dirty
page write outs no longer flood the work queue. (BZ#1125246)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:26.914-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:31.793-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:49.298-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124905"/>
          <criterion comment="kernel-PAE RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124911"/>
          <criterion comment="kernel-PAE-devel RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124926"/>
          <criterion comment="kernel-debug RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124876"/>
          <criterion comment="kernel-debug-devel RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124264"/>
          <criterion comment="kernel-devel RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124863"/>
          <criterion comment="kernel-doc RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124878"/>
          <criterion comment="kernel-headers RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124627"/>
          <criterion comment="kernel-xen RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:124852"/>
          <criterion comment="kernel-xen-devel RPM is earlier than 0:2.6.18-371.12.1.el5" test_ref="oval:org.mitre.oval:tst:123937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26750" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1243 -- automake security update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>automake</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1243.html" ref_id="ELSA-2014-1243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3386" ref_id="CVE-2012-3386"/>
        <description>Automake is a tool for automatically generating Makefile.in files compliant
with the GNU Coding Standards.

It was found that the distcheck rule in Automake-generated Makefiles made a
directory world-writable when preparing source archives. If a malicious,
local user could access this directory, they could execute arbitrary code
with the privileges of the user running &amp;quot;make distcheck&amp;quot;. (CVE-2012-3386)

Red Hat would like to thank Jim Meyering for reporting this issue. Upstream
acknowledges Stefano Lattarini as the original reporter.

All automake users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:15.466-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:31.063-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:48.610-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="automake RPM is earlier than 0:1.9.6-3.el5" test_ref="oval:org.mitre.oval:tst:124542"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26747" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0316 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0316.html" ref_id="ELSA-2014-0316"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1493" ref_id="CVE-2014-1493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1497" ref_id="CVE-2014-1497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1505" ref_id="CVE-2014-1505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1508" ref_id="CVE-2014-1508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1509" ref_id="CVE-2014-1509"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1510" ref_id="CVE-2014-1510"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1511" ref_id="CVE-2014-1511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1512" ref_id="CVE-2014-1512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1513" ref_id="CVE-2014-1513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1514" ref_id="CVE-2014-1514"/>
        <description>[24.4.0-1.0.1]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.4.0-1]
- Update to 24.4.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:34.406-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:47.788-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:21.869-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:21:28.814-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:21:28.814-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127287"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26715" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0016 -- gnupg security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnupg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0016.html" ref_id="ELSA-2014-0016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4576" ref_id="CVE-2013-4576"/>
        <description>[1.4.5-18.1]
- fix CVE-2013-4576 acoustic side channel attack on RSA private keys</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:28.587-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:44.410-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:20.516-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:34:07.198-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:34:07.198-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="gnupg is earlier than 0:1.4.5-18.el5_10.1" test_ref="oval:org.mitre.oval:tst:127974"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26714" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1814 -- php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1814.html" ref_id="ELSA-2013-1814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1398" ref_id="CVE-2011-1398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2688" ref_id="CVE-2012-2688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1643" ref_id="CVE-2013-1643"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6420" ref_id="CVE-2013-6420"/>
        <description>[5.1.6-43]
- drop unneeded patch

[5.1.6-42]
- add security fixes for CVE-2012-2688,
  CVE-2011-1398, CVE-2013-1643, CVE-2013-6420</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:36.342-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:43.778-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:20.227-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:24:49.559-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:24:49.559-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:127823"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128104"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128216"/>
          <criterion comment="php-common is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128272"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128065"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:127412"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:127819"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128196"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128286"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:127824"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128344"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:127936"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:127796"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128262"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128356"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128056"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128409"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:127877"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-43.el5_10" test_ref="oval:org.mitre.oval:tst:128349"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26702" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0121 -- mysql security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0121.html" ref_id="ELSA-2013-0121"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4452" ref_id="CVE-2012-4452"/>
        <description>[5.0.95-3]

- Re-add patch for CVE-2009-4030, mistakenly removed in 5.0.95 rebase

Resolves: CVE-2012-4452



[5.0.95-2]

- Support rotation of mysqld log (though this is not enabled by default)

Resolves: #647223

- Fix crash with EXPLAIN and prepared statements

Resolves: #654000

- Adopt init script updates from the last Fedora init script (F-15)

Resolves: #703476</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:53.046-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:43.189-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:19.815-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:28:52.770-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:28:52.770-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:130437"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:130240"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:130331"/>
          <criterion comment="mysql-server is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:130596"/>
          <criterion comment="mysql-test is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:130579"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26692" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0604 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0604.html" ref_id="ELSA-2013-0604"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1493" ref_id="CVE-2013-1493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0809" ref_id="CVE-2013-0809"/>
        <description>[ 1:1.6.0.0-1.36.1.11.9.0.1.el5_9]
- Add oracle-enterprise.patch

[1:1.6.0.0-1.36.1.11.9]
- Updated to icedtea6 1.11.9
- Resolves: rhbz#917176</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:46.228-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:42.720-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:19.537-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:41:58.800-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:41:58.800-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.36.1.11.9.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130141"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.36.1.11.9.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129467"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.36.1.11.9.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130096"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.36.1.11.9.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129567"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.36.1.11.9.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130050"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26687" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0614 -- xulrunner security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0614.html" ref_id="ELSA-2013-0614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0787" ref_id="CVE-2013-0787"/>
        <description>[17.0.3-2.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.3-2]
- Added fix for #848644</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:51.458-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:42.397-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:19.317-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:49:06.954-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:49:06.954-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129824"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130015"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129702"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129719"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26673" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-1790-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1790-1.html" ref_id="ELSA-2013-1790-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4355" ref_id="CVE-2013-4355"/>
        <description>kernel
[2.6.18-371.3.1.0.1]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:23.607-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:41.309-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:18.708-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128102 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:30.289-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:59.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128440"/>
          <criterion comment="ocfs2-2.6.18-371.3.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128227"/>
          <criterion comment="oracleasm-2.6.18-371.3.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128315"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128057"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128228"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128410"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128331"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128245"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128451"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127784"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128447"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.3.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128332"/>
          <criterion comment="ocfs2-2.6.18-371.3.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128126"/>
          <criterion comment="ocfs2-2.6.18-371.3.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128102"/>
          <criterion comment="ocfs2-2.6.18-371.3.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127747"/>
          <criterion comment="oracleasm-2.6.18-371.3.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128276"/>
          <criterion comment="oracleasm-2.6.18-371.3.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128362"/>
          <criterion comment="oracleasm-2.6.18-371.3.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128240"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26661" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-1034-1 -- kernel security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1034-1.html" ref_id="ELSA-2013-1034-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" ref_id="CVE-2013-1929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" ref_id="CVE-2012-6544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" ref_id="CVE-2012-6545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" ref_id="CVE-2013-0914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" ref_id="CVE-2013-3222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" ref_id="CVE-2013-3224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" ref_id="CVE-2013-3231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3235" ref_id="CVE-2013-3235"/>
        <description>kernel
[2.6.18-348.12.1.0.1]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printks when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:10.927-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:39.341-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:18.196-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35501 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:25.917-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:59.119-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129280"/>
          <criterion comment="ocfs2-2.6.18-348.12.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129252"/>
          <criterion comment="oracleasm-2.6.18-348.12.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128961"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129387"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:128661"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129398"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129291"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129161"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129340"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129384"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129204"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.12.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:129407"/>
          <criterion comment="ocfs2-2.6.18-348.12.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129345"/>
          <criterion comment="ocfs2-2.6.18-348.12.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:129310"/>
          <criterion comment="ocfs2-2.6.18-348.12.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128752"/>
          <criterion comment="oracleasm-2.6.18-348.12.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129406"/>
          <criterion comment="oracleasm-2.6.18-348.12.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:129312"/>
          <criterion comment="oracleasm-2.6.18-348.12.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26657" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1121 -- sos security update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1121.html" ref_id="ELSA-2013-1121"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2664" ref_id="CVE-2012-2664"/>
        <description>[1.7-9.62.0.1.el5_9.1]
- add patch to remove all sysrq echo commands from sysreport.legacy
  (John Sobecki) [orabug 11061754]
- comment out rh-upload-core and README.rh-upload-core in specfile

[1.7-9.62.el5_9.1]
- Remove anaconda-ks.cfg collection from general plug-in
  Resolves: bz965807

[1.7-9.62.el5_9]
- Elide passwords in anaconda-ks.cfg and yum.repos.d
  Resolves: bz965807</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:09.883-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:38.978-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:18.027-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:15:29.590-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:15:29.590-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sos is earlier than 0:1.7-9.62.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:128859"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26620" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3086 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3086.html" ref_id="ELSA-2014-3086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3611" ref_id="CVE-2014-3611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" ref_id="CVE-2014-3185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" ref_id="CVE-2014-3181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3535" ref_id="CVE-2014-3535"/>
        <description>kernel-uek
[2.6.32-400.36.10uek]
- USB: whiteheat: Added bounds checking for bulk command response (James Forshaw)  [Orabug: 19849336]  {CVE-2014-3185}
- HID: fix a couple of off-by-ones (Jiri Kosina)  [Orabug: 19849320]  {CVE-2014-3181}
logging macros to functions (Joe Perches)  [Orabug: 19847630]  {CVE-2014-3535}
logging macros to functions (Joe Perches)  [Orabug: 19847630] 
- vsprintf: Recursive vsnprintf: Add '%pV', struct va_format (Joe Perches)  [Orabug: 19847630] 
- KVM: x86: Improve thread safety in pit (Andy Honig)  [Orabug: 19905688]  {CVE-2014-3611}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:11.488-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:38.132-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:17.658-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35153 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:29.795-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:57.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126031"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126573"/>
            <criterion comment="ofa-2.6.32-400.36.10.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126434"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126390"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126326"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126528"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126516"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126624"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126559"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126243"/>
            <criterion comment="ofa-2.6.32-400.36.10.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126487"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126615"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126116"/>
            <criterion comment="ofa-2.6.32-400.36.10.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126591"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126133"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126089"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126652"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126266"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126450"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126536"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:125736"/>
            <criterion comment="ofa-2.6.32-400.36.10.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126503"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26617" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3047 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3047.html" ref_id="ELSA-2014-3047"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" ref_id="CVE-2014-4943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699" ref_id="CVE-2014-4699"/>
        <description>[2.6.39-400.215.4]
- l2tp: fix an unprivileged user to kernel privilege escalation (Sasha Levin)  [Orabug: 19229505]  {CVE-2014-4943} {CVE-2014-4943}
- ptrace,x86: force IRET path after a ptrace_stop() (Tejun Heo)  [Orabug: 19230690]  {CVE-2014-4699}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:09.010-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:37.628-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:17.412-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127361"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127508"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127325"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127076"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127410"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127257"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127459"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127310"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127273"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127524"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127399"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127441"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26614" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3077 -- bash security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3077.html" ref_id="ELSA-2014-3077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7169" ref_id="CVE-2014-7169"/>
        <description>[3.2-33.1.0.1]
- Preliminary fix for CVE-2014-7169</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:28.994-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:12.034-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:39.467-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="bash RPM is earlier than 0:3.2-33.el5.1.0.1" test_ref="oval:org.mitre.oval:tst:124527"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26595" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0926-1 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
          <product>ocfs2</product>
          <product>oracleasm</product>
          <product>kernel-PAE</product>
          <product>kernel-PAE-devel</product>
          <product>kernel-debug</product>
          <product>kernel-debug-devel</product>
          <product>kernel-devel</product>
          <product>kernel-doc</product>
          <product>kernel-headers</product>
          <product>kernel-xen</product>
          <product>kernel-xen-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0926-1.html" ref_id="ELSA-2014-0926-1"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2678" ref_id="CVE-2014-2678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4021" ref_id="CVE-2014-4021"/>
        <description>kernel
[2.6.18-371.11.1.0.1]
- ocfs2: dlm: fix recovery hung (Junxiao Bi) [orabug 13956772]
- i386: fix MTRR code (Zhenzhong Duan) [orabug 15862649]
- [oprofile] x86, mm: Add __get_user_pages_fast() [orabug 14277030]
- [oprofile] export __get_user_pages_fast() function [orabug 14277030]
- [oprofile] oprofile, x86: Fix nmi-unsafe callgraph support [orabug 14277030]
- [oprofile] oprofile: use KM_NMI slot for kmap_atomic [orabug 14277030]
- [oprofile] oprofile: i386 add get_user_pages_fast support [orabug 14277030]
- [kernel] Initialize the local uninitialized variable stats. [orabug 14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug 13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug 14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus (Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki, Chris Mason)
  [orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug 12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang) [orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin) [orabug 12687646]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
  (Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf (John Sobecki)
  [orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
  hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
  NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug 9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
  [orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
  [orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for (KOSAKI Motohiro,
  Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
- [usb] USB: fix __must_check warnings in drivers/usb/core/ (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix endpoint device creation (Junxiao Bi) [orabug 14795203]
- [usb] usbcore: fix refcount bug in endpoint removal (Junxiao Bi) [orabug 14795203]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:24.803-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:34.370-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:16.448-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127232 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:23.485-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:57.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127000"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.0.1.el5 is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127070"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.0.1.el5 is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:126406"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127043"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:126853"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:126793"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127044"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127174"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:126236"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127095"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:126598"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.11.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:127024"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.0.1.el5PAE is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127018"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.0.1.el5debug is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:126739"/>
          <criterion comment="ocfs2-2.6.18-371.11.1.0.1.el5xen is earlier than 0:1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127232"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.0.1.el5PAE is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127195"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.0.1.el5debug is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127214"/>
          <criterion comment="oracleasm-2.6.18-371.11.1.0.1.el5xen is earlier than 0:2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127130"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26566" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3015 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3015.html" ref_id="ELSA-2014-3015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0055" ref_id="CVE-2014-0055"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101" ref_id="CVE-2014-0101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523" ref_id="CVE-2014-2523"/>
        <description>[2.6.39-400.214.4]
- netfilter: nf_conntrack_dccp: fix skb_header_pointer API usages (Daniel Borkmann)  [Orabug: 18462070]  {CVE-2014-2523}
- net: sctp: fix sctp_sf_do_5_1D_ce to verify if we/peer is AUTH capable (Daniel Borkmann)  [Orabug: 18461090]  {CVE-2014-0101}
- vhost-net: insufficient handling of error conditions in get_rx_bufs() (Guangyu Sun)  [Orabug: 18461089]  {CVE-2014-0055}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:41.097-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:33.690-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:16.123-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127731"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127698"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:126999"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127694"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127664"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127591"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127629"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127722"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127790"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127949"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127670"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127837"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26561" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0186 -- mysql55-mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql55-mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0186.html" ref_id="ELSA-2014-0186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5908" ref_id="CVE-2013-5908"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0001" ref_id="CVE-2014-0001"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0386" ref_id="CVE-2014-0386"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0393" ref_id="CVE-2014-0393"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0401" ref_id="CVE-2014-0401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0402" ref_id="CVE-2014-0402"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0412" ref_id="CVE-2014-0412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0437" ref_id="CVE-2014-0437"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3839" ref_id="CVE-2013-3839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5807" ref_id="CVE-2013-5807"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5891" ref_id="CVE-2013-5891"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0420" ref_id="CVE-2014-0420"/>
        <description>[5.5.36-2]
- Fix CVE-2014-0001
  Related: #1055875

[5.5.36-1]
- Update to MySQL 5.5.36, for various fixes described at
  http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html
  Including fixes for CVE-2014-0412, CVE-2014-0437, CVE-2013-5908,
  CVE-2013-5807, CVE-2014-0420, CVE-2014-0393, CVE-2013-5891,
  CVE-2014-0386, CVE-2013-3839, CVE-2014-0401, CVE-2014-0402,
  Resolves: #1055875</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:21.935-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:32.150-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:15.463-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:10:40.806-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:10:40.806-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql55-mysql is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:127979"/>
          <criterion comment="mysql55-mysql-bench is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:127748"/>
          <criterion comment="mysql55-mysql-devel is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:127957"/>
          <criterion comment="mysql55-mysql-libs is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:128152"/>
          <criterion comment="mysql55-mysql-server is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:127718"/>
          <criterion comment="mysql55-mysql-test is earlier than 0:5.5.36-2.el5" test_ref="oval:org.mitre.oval:tst:127586"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26560" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0518 -- scsi-target-utils security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0518.html" ref_id="ELSA-2010-0518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2221" ref_id="CVE-2010-2221"/>
        <description>[0.0-6.20091205snap.3]
- Fix buffer overflow in isns scn handling (CVE-2010-2221)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T12:13:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-03T14:45:31.326-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:31.759-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:15.269-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:31:38.007-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:31:38.007-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="scsi-target-utils is earlier than 0:0.0-6.20091205snap.el5_5.3" test_ref="oval:org.mitre.oval:tst:126137"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26541" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1142 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1142.html" ref_id="ELSA-2013-1142"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1701" ref_id="CVE-2013-1701"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1709" ref_id="CVE-2013-1709"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1710" ref_id="CVE-2013-1710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1713" ref_id="CVE-2013-1713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1714" ref_id="CVE-2013-1714"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1717" ref_id="CVE-2013-1717"/>
        <description>[17.0.8-5.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.8-5]
- Update to 17.0.8 ESR
- Added strict aliasing patch (mozbz#821502)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:37.480-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:30.077-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:14.905-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:23:32.323-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:23:32.323-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129217"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26538" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3074 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3074.html" ref_id="ELSA-2014-3074"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" ref_id="CVE-2014-3917"/>
        <description>[2.6.39-400.215.10.el6uek]
- auditsc: audit_krule mask accesses need bounds checking (Andy 
Lutomirski)  [Orabug: 19590597]  {CVE-2014-3917}

[2.6.39-400.215.9.el6uek]
- oracleasm: Add support for new error return codes from block/SCSI 
(Martin K. Petersen)  [Orabug: 18438934]

[2.6.39-400.215.8.el6uek]
- ib_ipoib: CSUM support in connected mode (Yuval Shaia)  [Orabug: 
18692878] - net: Reduce high cpu usage in bonding driver by do_csum 
(Venkat Venkatsubra)  [Orabug: 18141731] - [random] Partially revert 
6d7c7e49: random: make 'add_interrupt_randomness() (John Sobecki) 
[Orabug: 17740293] - oracleasm: claim FMODE_EXCL access on disk during 
asm_open (Srinivas Eeda)  [Orabug: 19453460] - notify block layer when 
using temporary change to cache_type (Vaughan Cao)  [Orabug: 19448451] - 
sd: Fix parsing of 'temporary ' cache mode prefix (Ben Hutchings) 
[Orabug: 19448451] - sd: fix array cache flushing bug causing 
performance problems (James Bottomley)  [Orabug: 19448451] - block: fix 
max discard sectors limit (James Bottomley)  [Orabug: 18961244] - 
xen-netback: fix deadlock in high memory pressure (Junxiao Bi)  [Orabug: 
18959416] - sdp: fix keepalive functionality (shamir rabinovitch) 
[Orabug: 18728784] - SELinux: Fix possible NULL pointer dereference in 
selinux_inode_permission() (Steven Rostedt)  [Orabug: 18552029] - 
refcount: take rw_lock in ocfs2_reflink (Wengang Wang)  [Orabug: 
18406219] - ipv6: check return value for dst_alloc (Madalin Bucur) 
[Orabug: 17865160] - cciss: bug fix to prevent cciss from loading in 
kdump crash kernel (Mike Miller)  [Orabug: 17740446] - configfs: fix 
race between dentry put and lookup (Junxiao Bi)  [Orabug: 17627075]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:20.394-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:00.442-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:36.475-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124797"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124854"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124802"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124809"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124476"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124686"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124563"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124944"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124912"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124826"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124927"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124831"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26536" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1245 -- krb5 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1245.html" ref_id="ELSA-2014-1245"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4344" ref_id="CVE-2014-4344"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4341" ref_id="CVE-2014-4341"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1418" ref_id="CVE-2013-1418"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6800" ref_id="CVE-2013-6800"/>
        <description>Kerberos is an authentication system which allows clients and services to
authenticate to each other with the help of a trusted third party, a
Kerberos Key Distribution Center (KDC).

It was found that if a KDC served multiple realms, certain requests could
cause the setup_server_realm() function to dereference a NULL pointer.
A remote, unauthenticated attacker could use this flaw to crash the KDC
using a specially crafted request. (CVE-2013-1418, CVE-2013-6800)

A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO
acceptor for continuation tokens. A remote, unauthenticated attacker could
use this flaw to crash a GSSAPI-enabled server application. (CVE-2014-4344)

A buffer over-read flaw was found in the way MIT Kerberos handled certain
requests. A man-in-the-middle attacker with a valid Kerberos ticket who is
able to inject packets into a client or server application&amp;#39;s GSSAPI session
could use this flaw to crash the application. (CVE-2014-4341)

This update also fixes the following bugs:

* Prior to this update, the libkrb5 library occasionally attempted to free
already freed memory when encrypting credentials. As a consequence, the
calling process terminated unexpectedly with a segmentation fault.
With this update, libkrb5 frees memory correctly, which allows the
credentials to be encrypted appropriately and thus prevents the mentioned
crash. (BZ#1004632)

* Previously, when the krb5 client library was waiting for a response from
a server, the timeout variable in certain cases became a negative number.
Consequently, the client could enter a loop while checking for responses.
With this update, the client logic has been modified and the described
error no longer occurs. (BZ#1089732)

All krb5 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the krb5kdc daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:15.790-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:00.146-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:35.835-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5-devel RPM is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:124845"/>
          <criterion comment="krb5-libs RPM is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:124467"/>
          <criterion comment="krb5-server RPM is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:124692"/>
          <criterion comment="krb5-server-ldap RPM is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:124918"/>
          <criterion comment="krb5-workstation RPM is earlier than 0:1.6.1-78.el5" test_ref="oval:org.mitre.oval:tst:124842"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26512" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2542 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2542.html" ref_id="ELSA-2013-2542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" ref_id="CVE-2012-6544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" ref_id="CVE-2013-2206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" ref_id="CVE-2013-2232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" ref_id="CVE-2013-2237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2851" ref_id="CVE-2013-2851"/>
        <description>kernel-uek
[2.6.32-400.29.3uek]
- block: do not pass disk names as format strings (Jerry Snitselaar) [Orabug: 17230124] {CVE-2013-2851}
- af_key: initialize satype in key_notify_policy_flush() (Nicolas Dichtel) [Orabug: 17370765] {CVE-2013-2237}
- Bluetooth: L2CAP - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17371054] {CVE-2012-6544}
- Bluetooth: HCI - Fix info leak in getsockopt(HCI_FILTER) (Mathias Krause) [Orabug: 17371072] {CVE-2012-6544}
- ipv6: ip6_sk_dst_check() must not assume ipv6 dst (Eric Dumazet) [Orabug: 17371079] {CVE-2013-2232}
- sctp: Use correct sideffect command in duplicate cookie handling (Vlad Yasevich) [Orabug: 17371121] {CVE-2013-2206}
- sctp: deal with multiple COOKIE_ECHO chunks (Max Matveev) [Orabug: 17372129] {CVE-2013-2206}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:14.235-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:25.844-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:12.564-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128834 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:23.730-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:53.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128563"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128825"/>
            <criterion comment="ofa-2.6.32-400.29.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128632"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128314"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128403"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128435"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:129153"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:129150"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:129067"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129148"/>
            <criterion comment="ofa-2.6.32-400.29.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128452"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128543"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128834"/>
            <criterion comment="ofa-2.6.32-400.29.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129078"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:129115"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128854"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128734"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:129111"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128886"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:129170"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128796"/>
            <criterion comment="ofa-2.6.32-400.29.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128540"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26446" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1790 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1790.html" ref_id="ELSA-2013-1790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4355" ref_id="CVE-2013-4355"/>
        <description>kernel
[2.6.18-371.3.1]
- [net] be2net: don't use GRO for packets w/ re-inserted VLAN tags (Ivan Vecera) [1023348 1008691]
- [net] tg3: call pci_enable_wake() to set power state (John Feeney) [1014973 996331]
- [misc] backport fixes for percpu-rw-semaphore (Mikulas Patocka) [1014715 867997]
- [xen] information leak via I/O instruction emulation (Igor Mammedov) [1009602 1009603] {CVE-2013-4355}

[2.6.18-371.2.1]
- [scsi] mpt2sas: bump version (Tomas Henzl) [1018458 956330]
- [scsi] mpt2sas: fix the incorrect scsi_dma_map error checking (Tomas Henzl) [1018458 956330]
- [xen] x86: check segment descriptor read result in 64-bit OUTS emulation (Radim Krcmar) [1012958 1012959] {CVE-2013-4368}
- [md] dm snapshot: fix data corruption (Mikulas Patocka) [1004734 975353] {CVE-2013-4299}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:25.311-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:24.279-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:11.372-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:59:21.488-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:59:21.488-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:127939"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.3.1.el5-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128361"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.3.1.el5-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:127886"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:128424"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:128288"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:127906"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:128204"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:127893"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:127507"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:128242"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:128418"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.3.1.el5" test_ref="oval:org.mitre.oval:tst:128291"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.3.1.el5PAE-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128444"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.3.1.el5debug-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:127678"/>
          <criterion comment="ocfs2 is earlier than 0:2.6.18-371.3.1.el5xen-1.4.10-1.el5" test_ref="oval:org.mitre.oval:tst:128295"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.3.1.el5PAE-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128055"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.3.1.el5debug-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128137"/>
          <criterion comment="oracleasm is earlier than 0:2.6.18-371.3.1.el5xen-2.0.5-1.el5" test_ref="oval:org.mitre.oval:tst:128267"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26440" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1813 -- php53 and php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1813.html" ref_id="ELSA-2013-1813"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6420" ref_id="CVE-2013-6420"/>
        <description>[5.3.3-27]
- add security fix for CVE-2013-6420</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:48.238-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:23.600-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:10.847-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:07:10.976-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:07:10.976-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127642"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128359"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128275"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128392"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128068"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128177"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128364"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128402"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128251"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127621"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127973"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128382"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128401"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128343"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128155"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128100"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128281"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128293"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128075"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127463"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128199"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128229"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127689"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128380"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128385"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128032"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128340"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128339"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128282"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128302"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128303"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128194"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127833"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128289"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128252"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128341"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128239"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128025"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128244"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128156"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127962"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128145"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128395"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127619"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128327"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128222"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128311"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128381"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26425" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1868 -- xorg-x11-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1868.html" ref_id="ELSA-2013-1868"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6424" ref_id="CVE-2013-6424"/>
        <description>[1.13.0-23.1]
- Fix root window damage reports when Xinerama is active (#919165)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:39.229-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:22.710-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:10.052-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:24:56.670-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:24:56.670-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127293"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127955"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128269"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128279"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127753"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127804"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128077"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128294"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127945"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:128109"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127850"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127946"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:128265"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127820"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:128045"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127316"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127794"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26417" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0362 -- scsi-target-utils security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0362.html" ref_id="ELSA-2010-0362"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0743" ref_id="CVE-2010-0743"/>
        <description>[0.0-6.20091205snap.2]
- 576359 Fix format string vulnerability  (CVE-2010-0743)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T12:13:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-03T14:45:31.823-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:21.346-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:09.815-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:42:01.344-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:42:01.344-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="scsi-target-utils is earlier than 0:0.0-6.20091205snap.el5_5.2" test_ref="oval:org.mitre.oval:tst:126426"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26408" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0247 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0247.html" ref_id="ELSA-2014-0247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0092" ref_id="CVE-2014-0092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5138" ref_id="CVE-2009-5138"/>
        <description>[1.4.1-14]
- Renamed gnutls-1.4.1-cve-2014-0092-1.patch to cve-2014-5138.patch
- Renamed gnutls-1.4.1-cve-2014-0092-2.patch to cve-2014-0092.patch

[1.4.1-13]
- fix issues of CVE-2014-0092 (#1069888)

[1.4.1-12]
- fix CVE-2013-2116 - fix DoS regression in CVE-2013-1619
  upstream patch (#966754)

[1.4.1-11]
- fix CVE-2013-1619 - fix TLS-CBC timing attack (#908238)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:23.362-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:20.397-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:09.140-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:25:38.692-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:25:38.692-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:127238"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:127992"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:128129"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26392" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0474 -- struts security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>struts</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0474.html" ref_id="ELSA-2014-0474"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0114" ref_id="CVE-2014-0114"/>
        <description>[1.2.9-4jpp.7]
- Resolves: rhbz#1092457
- CVE-2014-0114: Fixed ClassLoader manipulation vulnerability
- Added dist tag to release</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:26.418-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:20.098-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:08.943-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:47:29.994-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:47:29.994-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="struts is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:127365"/>
          <criterion comment="struts-javadoc is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:127608"/>
          <criterion comment="struts-manual is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:127712"/>
          <criterion comment="struts-webapps-tomcat5 is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:127431"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26302" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1677 -- wireshark security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1677.html" ref_id="ELSA-2014-1677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6421" ref_id="CVE-2014-6421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6422" ref_id="CVE-2014-6422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6423" ref_id="CVE-2014-6423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6425" ref_id="CVE-2014-6425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6428" ref_id="CVE-2014-6428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6429" ref_id="CVE-2014-6429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6430" ref_id="CVE-2014-6430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6431" ref_id="CVE-2014-6431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6432" ref_id="CVE-2014-6432"/>
        <description>[1.0.15-7.0.1.el5]
        - Added oracle-ocfs2-network.patch
        - increase max packet size to 65536 (Herbert van den Bergh) [orabug 13542633]

        [1.0.15-7]
        - security patches
        - Resolves: CVE-2014-6421
                    CVE-2014-6423
                    CVE-2014-6425
                    CVE-2014-6428
                    CVE-2014-6429</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:19.459-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:15.927-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:06.799-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="wireshark is earlier than 0:1.0.15-7.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126636"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-7.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126550"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26189" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3073 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3073.html" ref_id="ELSA-2014-3073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" ref_id="CVE-2014-3917"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0205" ref_id="CVE-2014-0205"/>
        <description>kernel-uek
[2.6.32-400.36.8.el6uek]
- auditsc: audit_krule mask accesses need bounds checking (Andy 
Lutomirski)  [Orabug: 19590638]  {CVE-2014-3917}
- futex: Fix errors in nested key ref-counting (Darren Hart)  [Orabug: 
19590443]  {CVE-2014-0205}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:19.030-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:00:33.902-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:29.167-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124515 - Corrected package names in objects and versions in states." date="2015-02-26T18:54:00.627-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2015-02-26T19:18:40.076-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:50.156-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124678"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124667"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124747"/>
            <criterion comment="kernel-uek-headers RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124583"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124859"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124850"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124939"/>
            <criterion comment="ofa-2.6.32-400.36.8.el6uek RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124869"/>
            <criterion comment="ofa-2.6.32-400.36.8.el6uekdebug RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124913"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el6uek RPM is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:124773"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el6uekdebug RPM is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:124794"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124951"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124408"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124766"/>
            <criterion comment="kernel-uek-headers RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124460"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124375"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124017"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124889"/>
            <criterion comment="ofa-2.6.32-400.36.8.el5uek RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124515"/>
            <criterion comment="ofa-2.6.32-400.36.8.el5uekdebug RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124479"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el5uek RPM is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:124934"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el5uekdebug RPM is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:124921"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26179" version="6" class="patch">
      <metadata>
        <title>ELSA-2014-1634 -- java-1.6.0-openjdk security and bug fix update</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1634.html" ref_id="ELSA-2014-1634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6457" ref_id="CVE-2014-6457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6502" ref_id="CVE-2014-6502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6504" ref_id="CVE-2014-6504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6506" ref_id="CVE-2014-6506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6511" ref_id="CVE-2014-6511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6512" ref_id="CVE-2014-6512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6517" ref_id="CVE-2014-6517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6519" ref_id="CVE-2014-6519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6531" ref_id="CVE-2014-6531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6558" ref_id="CVE-2014-6558"/>
        <description>[1:1.6.0.33-1.13.5.0]

- Update to IcedTea 1.13.5

- Remove upstreamed patches.

- Regenerate add-final-location-rpaths patch against new release.

- Change versioning to match java-1.7.0-openjdk so revisions work.

- Use xz for tarballs to reduce file size.

- No need to explicitly disable system LCMS any more (bug fixed upstream).

- Add icedteasnapshot to setup lines so they work with pre-release tarballs.

- Resolves: rhbz#1148901</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:18.274-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26179 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:00:27.228-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:18.587-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126306 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:43.596-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:26.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126377"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126335"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126343"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126241"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126149"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125953"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126306"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126176"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126246"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126297"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126393"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126362"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126469"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126402"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25183" version="3" class="inventory">
      <metadata>
        <title>Oracle Linux 7.x</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
        </affected>
        <reference ref_id="cpe:/o:oracle:linux:7" source="CPE"/>
        <description>The operating system installed on the system is Oracle Linux 7.x</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-23T11:44:52.851-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:00:56.441-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:01.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="Oracle Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115464"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26119" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1246 -- nss and nspr security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1246.html" ref_id="ELSA-2014-1246"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1740" ref_id="CVE-2013-1740"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1490" ref_id="CVE-2014-1490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1491" ref_id="CVE-2014-1491"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1492" ref_id="CVE-2014-1492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1545" ref_id="CVE-2014-1545"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

A flaw was found in the way TLS False Start was implemented in NSS.
An attacker could use this flaw to potentially return unencrypted
information from the server. (CVE-2013-1740)

A race condition was found in the way NSS implemented session ticket
handling as specified by RFC 5077. An attacker could use this flaw to crash
an application using NSS or, in rare cases, execute arbitrary code with the
privileges of the user running that application. (CVE-2014-1490)

It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE)
parameters. This could possibly lead to weak encryption being used in
communication between the client and the server. (CVE-2014-1491)

An out-of-bounds write flaw was found in NSPR. A remote attacker could
potentially use this flaw to crash an application using NSPR or, possibly,
execute arbitrary code with the privileges of the user running that
application. This NSPR flaw was not exposed to web content in any shipped
version of Firefox. (CVE-2014-1545)

It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)

Red Hat would like to thank the Mozilla project for reporting the
CVE-2014-1490, CVE-2014-1491, and CVE-2014-1545 issues. Upstream
acknowledges Brian Smith as the original reporter of CVE-2014-1490, Antoine
Delignat-Lavaud and Karthikeyan Bhargavan as the original reporters of
CVE-2014-1491, and Abhishek Arya as the original reporter of CVE-2014-1545.

The nss and nspr packages have been upgraded to upstream version 3.16.1 and
4.10.6 respectively, which provide a number of bug fixes and enhancements
over the previous versions. (BZ#1110857, BZ#1110860)

This update also fixes the following bugs:

* Previously, when the output.log file was not present on the system, the
shell in the Network Security Services (NSS) specification handled test
failures incorrectly as false positive test results. Consequently, certain
utilities, such as &amp;quot;grep&amp;quot;, could not handle failures properly. This update
improves error detection in the specification file, and &amp;quot;grep&amp;quot; and other
utilities now handle missing files or crashes as intended. (BZ#1035281)

* Prior to this update, a subordinate Certificate Authority (CA) of the
ANSSI agency incorrectly issued an intermediate certificate installed on a
network monitoring device. As a consequence, the monitoring device was
enabled to act as an MITM (Man in the Middle) proxy performing traffic
management of domain names or IP addresses that the certificate holder did
not own or control. The trust in the intermediate certificate to issue the
certificate for an MITM device has been revoked, and such a device can no
longer be used for MITM attacks. (BZ#1042684)

* Due to a regression, MD5 certificates were rejected by default because
Network Security Services (NSS) did not trust MD5 certificates. With this
update, MD5 certificates are supported in Red Hat Enterprise Linux 5.
(BZ#11015864)

Users of nss and nspr are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:30.561-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:00:29.800-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:25.456-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nss RPM is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:124629"/>
          <criterion comment="nss-devel RPM is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:123976"/>
          <criterion comment="nss-pkcs11-devel RPM is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:124772"/>
          <criterion comment="nss-tools RPM is earlier than 0:3.16.1-2.el5" test_ref="oval:org.mitre.oval:tst:124843"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25198" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0742: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0742-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0742.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1533" ref_url="http://linux.oracle.com/cve/CVE-2014-1533.html" source="CVE"/>
        <reference ref_id="CVE-2014-1538" ref_url="http://linux.oracle.com/cve/CVE-2014-1538.html" source="CVE"/>
        <reference ref_id="CVE-2014-1541" ref_url="http://linux.oracle.com/cve/CVE-2014-1541.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.6.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.6.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:52.351-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25198 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:58.312-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:03.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115644"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:115405"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25185" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0508: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0508-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0508.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-0878" ref_url="http://linux.oracle.com/cve/CVE-2014-0878.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.
This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-2428, CVE-2014-0446, CVE-2014-0452,
CVE-2014-0451, CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414,
CVE-2014-2412, CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629,
CVE-2014-2401, CVE-2014-0449, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)
All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 6 SR16 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:49.765-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25185 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:56.530-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:02.017-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115494"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115319"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115604"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115658"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115515"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115393"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115654"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115481"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115385"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115225"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115554"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115547"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115499"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115616"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115573"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25170" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0745: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0745-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0745.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0531" ref_url="http://linux.oracle.com/cve/CVE-2014-0531.html" source="CVE"/>
        <reference ref_id="CVE-2014-0532" ref_url="http://linux.oracle.com/cve/CVE-2014-0532.html" source="CVE"/>
        <reference ref_id="CVE-2014-0533" ref_url="http://linux.oracle.com/cve/CVE-2014-0533.html" source="CVE"/>
        <reference ref_id="CVE-2014-0534" ref_url="http://linux.oracle.com/cve/CVE-2014-0534.html" source="CVE"/>
        <reference ref_id="CVE-2014-0535" ref_url="http://linux.oracle.com/cve/CVE-2014-0535.html" source="CVE"/>
        <reference ref_id="CVE-2014-0536" ref_url="http://linux.oracle.com/cve/CVE-2014-0536.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-16,
listed in the References section.
Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0534, CVE-2014-0535, CVE-2014-0536)
Multiple flaws in flash-plugin could allow an attacker to conduct
cross-site scripting (XSS) attacks if a victim were tricked into visiting a
specially crafted web page. (CVE-2014-0531, CVE-2014-0532, CVE-2014-0533)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.378.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:49.334-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25170 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:54.797-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:01.075-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el5" test_ref="oval:org.mitre.oval:tst:114686"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el6" test_ref="oval:org.mitre.oval:tst:115556"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25106" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0626: openssl097a and openssl098e security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference ref_id="ELSA-2014:0626-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0626.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0224" ref_url="http://linux.oracle.com/cve/CVE-2014-0224.html" source="CVE"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)
Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433
Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.
All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:53.445-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25106 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:50.521-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:58.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" test_ref="oval:org.mitre.oval:tst:115670"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="openssl098e is earlier than 0:0.9.8e-18.el6_5.2" test_ref="oval:org.mitre.oval:tst:115424"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25095" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0624: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2014:0624-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0624.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0224" ref_url="http://linux.oracle.com/cve/CVE-2014-0224.html" source="CVE"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)
Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433
Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.
All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:58.787-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25095 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:49.716-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:57.711-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:115514"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:114923"/>
          <criterion comment="openssl is earlier than 0:0.9.8e-27.el5_10.3" test_ref="oval:org.mitre.oval:tst:115680"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25005" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0741: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2014:0741-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0741.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1533" ref_url="http://linux.oracle.com/cve/CVE-2014-1533.html" source="CVE"/>
        <reference ref_id="CVE-2014-1538" ref_url="http://linux.oracle.com/cve/CVE-2014-1538.html" source="CVE"/>
        <reference ref_id="CVE-2014-1541" ref_url="http://linux.oracle.com/cve/CVE-2014-1541.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.6.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.6.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:59.127-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25005 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:43.145-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:55.401-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115530"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:115118"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115529"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115454"/>
            <criterion comment="xulrunner is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115428"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24953" version="3" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 7</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:7"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 7.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:29.153-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:42.013-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:58.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 7 is installed" test_ref="oval:org.mitre.oval:tst:115398"/>
        <criterion negate="true" comment="Oracle Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115342"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24939" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0474: struts security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>struts</product>
        </affected>
        <reference ref_id="ELSA-2014:0474-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0474.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0114" ref_url="http://linux.oracle.com/cve/CVE-2014-0114.html" source="CVE"/>
        <description>Apache Struts is a framework for building web applications with Java.
It was found that the Struts 1 ActionForm object allowed access to the
'class' parameter, which is directly mapped to the getClass() method. A
remote attacker could use this flaw to manipulate the ClassLoader used by
an application server running Struts 1. This could lead to remote code
execution under certain conditions. (CVE-2014-0114)
All struts users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
using struts must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:54.733-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24939 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:38.586-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:53.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="struts-manual is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:115352"/>
          <criterion comment="struts is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:115666"/>
          <criterion comment="struts-javadoc is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:115045"/>
          <criterion comment="struts-webapps-tomcat5 is earlier than 0:1.2.9-4jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:115613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24916" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0740: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2014:0740-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0740.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-7339" ref_url="http://linux.oracle.com/cve/CVE-2013-7339.html" source="CVE"/>
        <reference ref_id="CVE-2014-1737" ref_url="http://linux.oracle.com/cve/CVE-2014-1737.html" source="CVE"/>
        <reference ref_id="CVE-2014-1738" ref_url="http://linux.oracle.com/cve/CVE-2014-1738.html" source="CVE"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.
* A flaw was found in the way the Linux kernel's floppy driver handled user
space provided data in certain error code paths while processing FDRAWCMD
IOCTL commands. A local user with write access to /dev/fdX could use this
flaw to free (using the kfree() function) arbitrary kernel memory.
(CVE-2014-1737, Important)
* It was found that the Linux kernel's floppy driver leaked internal kernel
memory addresses to user space during the processing of the FDRAWCMD IOCTL
command. A local user with write access to /dev/fdX could use this flaw to
obtain information about the kernel heap arrangement. (CVE-2014-1738, Low)
Note: A local user with write access to /dev/fdX could use these two flaws
(CVE-2014-1737 in combination with CVE-2014-1738) to escalate their
privileges on the system.
* A NULL pointer dereference flaw was found in the rds_ib_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2013-7339, Moderate)
Red Hat would like to thank Matthew Daley for reporting CVE-2014-1737 and
CVE-2014-1738.
This update also fixes the following bugs:
* A bug in the futex system call could result in an overflow when passing
a very large positive timeout. As a consequence, the FUTEX_WAIT operation
did not work as intended and the system call was timing out immediately.
A backported patch fixes this bug by limiting very large positive timeouts
to the maximal supported value. (BZ#1091832)
* A new Linux Security Module (LSM) functionality related to the setrlimit
hooks should produce a warning message when used by a third party module
that could not cope with it. However, due to a programming error, the
kernel could print this warning message when a process was setting rlimits
for a different process, or if rlimits were modified by another than the
main thread even though there was no incompatible third party module. This
update fixes the relevant code and ensures that the kernel handles this
warning message correctly. (BZ#1092869)
* Previously, the kernel was unable to detect KVM on system boot if the
Hyper-V emulation was enabled. A patch has been applied to ensure that
both KVM and Hyper-V hypervisors are now correctly detected during system
boot. (BZ#1094152)
* A function in the RPC code responsible for verifying whether cached
credentials match the current process did not perform the check correctly.
The code checked only whether the groups in the current process
credentials appear in the same order as in the cached credentials but did
not ensure that no other groups are present in the cached credentials. As
a consequence, when accessing files in NFS mounts, a process with the same
UID and GID as the original process but with a non-matching group list
could have been granted an unauthorized access to a file, or under certain
circumstances, the process could have been wrongly prevented from
accessing the file. The incorrect test condition has been fixed and the
problem can no longer occur. (BZ#1095062)
* When being under heavy load, some Fibre Channel storage devices, such as
Hitachi and HP Open-V series, can send a logout (LOGO) message to the
host system. However, due to a bug in the lpfc driver, this could result
in a loss of active paths to the storage and the paths could not be
recovered without manual intervention. This update corrects the lpfc
driver to ensure automatic recovery of the lost paths to the storage in
this scenario. (BZ#1096061)
All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:50.642-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24916 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:37.041-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:52.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115652"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:114705"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115391"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115485"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115166"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115244"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115601"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115350"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115471"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115448"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:114701"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.9.1.el5" test_ref="oval:org.mitre.oval:tst:115146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24881" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0509: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0509-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0509.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0878" ref_url="http://linux.oracle.com/cve/CVE-2014-0878.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>IBM J2SE version 5.0 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.
This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-2427, CVE-2014-2412,
CVE-2014-0460, CVE-2013-6629, CVE-2014-2401, CVE-2014-0453, CVE-2014-2398,
CVE-2014-1876)
All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM J2SE 5.0 SR16-FP6 release. All running
instances of IBM Java must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:56.950-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24881 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:32.885-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:50.747-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115365"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114847"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115584"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115419"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115083"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115506"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115282"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115330"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115148"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115490"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115555"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115400"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115578"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115630"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115607"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24767" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0486: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0486-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0486.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-0878" ref_url="http://linux.oracle.com/cve/CVE-2014-0878.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>IBM Java SE version 7 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.
This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-0455, CVE-2014-2428, CVE-2014-0448,
CVE-2014-0454, CVE-2014-0446, CVE-2014-0452, CVE-2014-0451, CVE-2014-2402,
CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414, CVE-2014-2412,
CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629, CVE-2014-2401,
CVE-2014-0449, CVE-2014-0459, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)
All users of java-1.7.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 7 SR7 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:57.777-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24767 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:28.846-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:47.744-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115406"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115057"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115090"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115035"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115590"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115268"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115579"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115669"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115502"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115449"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115549"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115321"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24759" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0413: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0413-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0413.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:34.967-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:36.162-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:50.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24759 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:33.722-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:39.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113278"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114098"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113617"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113573"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113805"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113763"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114219"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114226"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113404"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114209"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113971"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24739" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0414: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2014:0414-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0414.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2437" ref_url="http://linux.oracle.com/cve/CVE-2013-2437.html" source="CVE"/>
        <reference ref_id="CVE-2013-2442" ref_url="http://linux.oracle.com/cve/CVE-2013-2442.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2451" ref_url="http://linux.oracle.com/cve/CVE-2013-2451.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2466" ref_url="http://linux.oracle.com/cve/CVE-2013-2466.html" source="CVE"/>
        <reference ref_id="CVE-2013-2468" ref_url="http://linux.oracle.com/cve/CVE-2013-2468.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3743" ref_url="http://linux.oracle.com/cve/CVE-2013-3743.html" source="CVE"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5776" ref_url="http://linux.oracle.com/cve/CVE-2013-5776.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5787" ref_url="http://linux.oracle.com/cve/CVE-2013-5787.html" source="CVE"/>
        <reference ref_id="CVE-2013-5789" ref_url="http://linux.oracle.com/cve/CVE-2013-5789.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5812" ref_url="http://linux.oracle.com/cve/CVE-2013-5812.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5818" ref_url="http://linux.oracle.com/cve/CVE-2013-5818.html" source="CVE"/>
        <reference ref_id="CVE-2013-5819" ref_url="http://linux.oracle.com/cve/CVE-2013-5819.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5824" ref_url="http://linux.oracle.com/cve/CVE-2013-5824.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5831" ref_url="http://linux.oracle.com/cve/CVE-2013-5831.html" source="CVE"/>
        <reference ref_id="CVE-2013-5832" ref_url="http://linux.oracle.com/cve/CVE-2013-5832.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5848" ref_url="http://linux.oracle.com/cve/CVE-2013-5848.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5852" ref_url="http://linux.oracle.com/cve/CVE-2013-5852.html" source="CVE"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5887" ref_url="http://linux.oracle.com/cve/CVE-2013-5887.html" source="CVE"/>
        <reference ref_id="CVE-2013-5888" ref_url="http://linux.oracle.com/cve/CVE-2013-5888.html" source="CVE"/>
        <reference ref_id="CVE-2013-5889" ref_url="http://linux.oracle.com/cve/CVE-2013-5889.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5898" ref_url="http://linux.oracle.com/cve/CVE-2013-5898.html" source="CVE"/>
        <reference ref_id="CVE-2013-5899" ref_url="http://linux.oracle.com/cve/CVE-2013-5899.html" source="CVE"/>
        <reference ref_id="CVE-2013-5902" ref_url="http://linux.oracle.com/cve/CVE-2013-5902.html" source="CVE"/>
        <reference ref_id="CVE-2013-5905" ref_url="http://linux.oracle.com/cve/CVE-2013-5905.html" source="CVE"/>
        <reference ref_id="CVE-2013-5906" ref_url="http://linux.oracle.com/cve/CVE-2013-5906.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0375" ref_url="http://linux.oracle.com/cve/CVE-2014-0375.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0387" ref_url="http://linux.oracle.com/cve/CVE-2014-0387.html" source="CVE"/>
        <reference ref_id="CVE-2014-0403" ref_url="http://linux.oracle.com/cve/CVE-2014-0403.html" source="CVE"/>
        <reference ref_id="CVE-2014-0410" ref_url="http://linux.oracle.com/cve/CVE-2014-0410.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0415" ref_url="http://linux.oracle.com/cve/CVE-2014-0415.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0418" ref_url="http://linux.oracle.com/cve/CVE-2014-0418.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0424" ref_url="http://linux.oracle.com/cve/CVE-2014-0424.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)
All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:27.291-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:28.976-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:41.984-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24739 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:27.074-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:33.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114114"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113753"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113881"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114212"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114326"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114325"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114102"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114227"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114091"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114156"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114320"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24731" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0536: mysql55-mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql55-mysql</product>
        </affected>
        <reference ref_id="ELSA-2014:0536-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0536.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0384" ref_url="http://linux.oracle.com/cve/CVE-2014-0384.html" source="CVE"/>
        <reference ref_id="CVE-2014-2419" ref_url="http://linux.oracle.com/cve/CVE-2014-2419.html" source="CVE"/>
        <reference ref_id="CVE-2014-2430" ref_url="http://linux.oracle.com/cve/CVE-2014-2430.html" source="CVE"/>
        <reference ref_id="CVE-2014-2431" ref_url="http://linux.oracle.com/cve/CVE-2014-2431.html" source="CVE"/>
        <reference ref_id="CVE-2014-2432" ref_url="http://linux.oracle.com/cve/CVE-2014-2432.html" source="CVE"/>
        <reference ref_id="CVE-2014-2436" ref_url="http://linux.oracle.com/cve/CVE-2014-2436.html" source="CVE"/>
        <reference ref_id="CVE-2014-2438" ref_url="http://linux.oracle.com/cve/CVE-2014-2438.html" source="CVE"/>
        <reference ref_id="CVE-2014-2440" ref_url="http://linux.oracle.com/cve/CVE-2014-2440.html" source="CVE"/>
        <description>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.
This update fixes several vulnerabilities in the MySQL database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2014-2436,
CVE-2014-2440, CVE-2014-0384, CVE-2014-2419, CVE-2014-2430, CVE-2014-2431,
CVE-2014-2432, CVE-2014-2438)
These updated packages upgrade MySQL to version 5.5.37. Refer to the MySQL
Release Notes listed in the References section for a complete list of
changes.
All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:53.000-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24731 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:27.865-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:47.143-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql55-mysql-test is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:115031"/>
          <criterion comment="mysql55-mysql-libs is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:115583"/>
          <criterion comment="mysql55-mysql is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:115533"/>
          <criterion comment="mysql55-mysql-devel is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:115591"/>
          <criterion comment="mysql55-mysql-bench is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:115569"/>
          <criterion comment="mysql55-mysql-server is earlier than 0:5.5.37-1.el5" test_ref="oval:org.mitre.oval:tst:115392"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24708" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0449: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0449-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0449.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Thunderbird resolved hosts in
certain circumstances. An attacker could use this flaw to crash Thunderbird
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Thunderbird decoded JPEG
images. Loading an email or a web page containing a specially crafted JPEG
image could cause Thunderbird to crash. (CVE-2014-1523)
A flaw was found in the way Thunderbird handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith and Jesse
Schwartzentrube as the original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:32.909-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:25.672-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:39.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24708 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:21.599-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:31.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114236"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114183"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24662" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0407: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0407-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0407.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.
An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)
Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)
Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)
Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)
Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)
It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)
It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)
It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)
An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)
All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:33.995-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:20.982-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:36.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24662 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:17.762-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:28.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:114094"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:113865"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:113710"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:114147"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.55-2.4.7.1.el5_10" test_ref="oval:org.mitre.oval:tst:114068"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24610" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0414: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2014:0414-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0414.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2437" ref_url="http://linux.oracle.com/cve/CVE-2013-2437.html" source="CVE"/>
        <reference ref_id="CVE-2013-2442" ref_url="http://linux.oracle.com/cve/CVE-2013-2442.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2451" ref_url="http://linux.oracle.com/cve/CVE-2013-2451.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2466" ref_url="http://linux.oracle.com/cve/CVE-2013-2466.html" source="CVE"/>
        <reference ref_id="CVE-2013-2468" ref_url="http://linux.oracle.com/cve/CVE-2013-2468.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3743" ref_url="http://linux.oracle.com/cve/CVE-2013-3743.html" source="CVE"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5776" ref_url="http://linux.oracle.com/cve/CVE-2013-5776.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5787" ref_url="http://linux.oracle.com/cve/CVE-2013-5787.html" source="CVE"/>
        <reference ref_id="CVE-2013-5789" ref_url="http://linux.oracle.com/cve/CVE-2013-5789.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5812" ref_url="http://linux.oracle.com/cve/CVE-2013-5812.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5818" ref_url="http://linux.oracle.com/cve/CVE-2013-5818.html" source="CVE"/>
        <reference ref_id="CVE-2013-5819" ref_url="http://linux.oracle.com/cve/CVE-2013-5819.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5824" ref_url="http://linux.oracle.com/cve/CVE-2013-5824.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5831" ref_url="http://linux.oracle.com/cve/CVE-2013-5831.html" source="CVE"/>
        <reference ref_id="CVE-2013-5832" ref_url="http://linux.oracle.com/cve/CVE-2013-5832.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5848" ref_url="http://linux.oracle.com/cve/CVE-2013-5848.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5852" ref_url="http://linux.oracle.com/cve/CVE-2013-5852.html" source="CVE"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5887" ref_url="http://linux.oracle.com/cve/CVE-2013-5887.html" source="CVE"/>
        <reference ref_id="CVE-2013-5888" ref_url="http://linux.oracle.com/cve/CVE-2013-5888.html" source="CVE"/>
        <reference ref_id="CVE-2013-5889" ref_url="http://linux.oracle.com/cve/CVE-2013-5889.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5898" ref_url="http://linux.oracle.com/cve/CVE-2013-5898.html" source="CVE"/>
        <reference ref_id="CVE-2013-5899" ref_url="http://linux.oracle.com/cve/CVE-2013-5899.html" source="CVE"/>
        <reference ref_id="CVE-2013-5902" ref_url="http://linux.oracle.com/cve/CVE-2013-5902.html" source="CVE"/>
        <reference ref_id="CVE-2013-5905" ref_url="http://linux.oracle.com/cve/CVE-2013-5905.html" source="CVE"/>
        <reference ref_id="CVE-2013-5906" ref_url="http://linux.oracle.com/cve/CVE-2013-5906.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0375" ref_url="http://linux.oracle.com/cve/CVE-2014-0375.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0387" ref_url="http://linux.oracle.com/cve/CVE-2014-0387.html" source="CVE"/>
        <reference ref_id="CVE-2014-0403" ref_url="http://linux.oracle.com/cve/CVE-2014-0403.html" source="CVE"/>
        <reference ref_id="CVE-2014-0410" ref_url="http://linux.oracle.com/cve/CVE-2014-0410.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0415" ref_url="http://linux.oracle.com/cve/CVE-2014-0415.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0418" ref_url="http://linux.oracle.com/cve/CVE-2014-0418.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0424" ref_url="http://linux.oracle.com/cve/CVE-2014-0424.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)
All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:40.312-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:07.857-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:28.115-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24610 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:25.586-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:06:44.834-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:06:44.834-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114081"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114116"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113751"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114255"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114259"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113644"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114223"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114276"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114113"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113978"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114278"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24604" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0433: kernel security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2014:0433-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0433.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6638" ref_url="http://linux.oracle.com/cve/CVE-2012-6638.html" source="CVE"/>
        <reference ref_id="CVE-2013-2888" ref_url="http://linux.oracle.com/cve/CVE-2013-2888.html" source="CVE"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.
* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled TCP packets with both the SYN and FIN flags set.
A remote attacker could use this flaw to consume an excessive amount of
resources on the target system, potentially resulting in a denial of
service. (CVE-2012-6638, Moderate)
* A flaw was found in the way the Linux kernel handled HID (Human Interface
Device) reports with an out-of-bounds Report ID. An attacker with physical
access to the system could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2013-2888,
Moderate)
This update also fixes the following bugs:
* A previous change to the sunrpc code introduced a race condition between
the rpc_wake_up_task() and rpc_wake_up_status() functions. A race between
threads operating on these functions could result in a deadlock situation,
subsequently triggering a "soft lockup" event and rendering the system
unresponsive. This problem has been fixed by re-ordering tasks in the RPC
wait queue. (BZ#1073731)
* Running a process in the background on a GFS2 file system could
sometimes trigger a glock recursion error that resulted in a kernel panic.
This happened when a readpage operation attempted to take a glock that had
already been held by another function. To prevent this error, GFS2 now
verifies whether the glock is already held when performing the readpage
operation. (BZ#1073953)
* A previous patch backport to the IUCV (Inter User Communication Vehicle)
code was incomplete. Consequently, when establishing an IUCV connection,
the kernel could, under certain circumstances, dereference a NULL pointer,
resulting in a kernel panic. A patch has been applied to correct this
problem by calling the proper function when removing IUCV paths.
(BZ#1077045)
In addition, this update adds the following enhancement:
* The lpfc driver had a fixed timeout of 60 seconds for SCSI task
management commands. With this update, the lpfc driver enables the user to
set this timeout within the range from 5 to 180 seconds. The timeout can
be changed by modifying the "lpfc_task_mgmt_tmo" parameter for the lpfc
driver. (BZ#1073123)
All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:39.640-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:07.116-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:27.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24604 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:27.523-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:25.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114140"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114221"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114154"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114128"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114239"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:113700"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:113908"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114206"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114224"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114155"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114267"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.8.1.el5" test_ref="oval:org.mitre.oval:tst:114132"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24586" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0413: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0413-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0413.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:34.854-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:03.062-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:25.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24586 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.962-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:05:37.446-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:05:37.446-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113800"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114265"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113633"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113954"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114254"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114101"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114315"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114056"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114311"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114166"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114159"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24559" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0330: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2014:0330-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0330.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6150" ref_url="http://linux.oracle.com/cve/CVE-2012-6150.html" source="CVE"/>
        <reference ref_id="CVE-2013-4496" ref_url="http://linux.oracle.com/cve/CVE-2013-4496.html" source="CVE"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.
It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)
A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)
Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and Sam Richardson for reporting CVE-2012-6150. Upstream acknowledges
Andrew Bartlett as the original reporter of CVE-2013-4496.
All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:25.822-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.940-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24559 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:27.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113767"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113750"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113491"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113328"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113791"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113386"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113782"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113510"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113847"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112879"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113777"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113679"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113580"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112958"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113387"/>
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113629"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113690"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113821"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113721"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24517" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0594: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2014:0594-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0594.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-3466" ref_url="http://linux.oracle.com/cve/CVE-2014-3466.html" source="CVE"/>
        <reference ref_id="CVE-2014-3467" ref_url="http://linux.oracle.com/cve/CVE-2014-3467.html" source="CVE"/>
        <reference ref_id="CVE-2014-3468" ref_url="http://linux.oracle.com/cve/CVE-2014-3468.html" source="CVE"/>
        <reference ref_id="CVE-2014-3469" ref_url="http://linux.oracle.com/cve/CVE-2014-3469.html" source="CVE"/>
        <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). The gnutls packages also
include the libtasn1 library, which provides Abstract Syntax Notation One
(ASN.1) parsing and structures management, and Distinguished Encoding Rules
(DER) encoding and decoding functions.
A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)
It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)
Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)
Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)
Red Hat would like to thank GnuTLS upstream for reporting these issues.
Upstream acknowledges Joonas Kuorilehto of Codenomicon as the original
reporter of CVE-2014-3466.
Users of GnuTLS are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the GnuTLS or libtasn1 library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:55.494-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24517 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:23.598-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:43.212-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnutls is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:115598"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:115639"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-16.el5_10" test_ref="oval:org.mitre.oval:tst:114828"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24509" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0348: xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xalan-j2</product>
        </affected>
        <reference ref_id="ELSA-2014:0348-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0348.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0107" ref_url="http://linux.oracle.com/cve/CVE-2014-0107.html" source="CVE"/>
        <description>Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types.
It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features.
A remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses
Xalan-Java. (CVE-2014-0107)
All xalan-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:27.651-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.176-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24509 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:26.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113758"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113745"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113674"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113471"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113845"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113714"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113631"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113744"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113691"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113547"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24494" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0330: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2014:0330-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0330.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6150" ref_url="http://linux.oracle.com/cve/CVE-2012-6150.html" source="CVE"/>
        <reference ref_id="CVE-2013-4496" ref_url="http://linux.oracle.com/cve/CVE-2013-4496.html" source="CVE"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.
It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)
A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)
Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and Sam Richardson for reporting CVE-2012-6150. Upstream acknowledges
Andrew Bartlett as the original reporter of CVE-2013-4496.
All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:42.019-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:37.592-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24494 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:25.693-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:05:02.158-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:05:02.158-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113587"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113390"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113575"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113253"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113449"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113318"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113526"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113227"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113210"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113238"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113243"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113544"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113411"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113021"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113139"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113452"/>
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113614"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113379"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113196"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113603"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24493" version="11" class="patch">
      <metadata>
        <title>ELSA-2014:0211: postgresql84 and postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2014:0211-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0211.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0060" ref_url="http://linux.oracle.com/cve/CVE-2014-0060.html" source="CVE"/>
        <reference ref_id="CVE-2014-0061" ref_url="http://linux.oracle.com/cve/CVE-2014-0061.html" source="CVE"/>
        <reference ref_id="CVE-2014-0062" ref_url="http://linux.oracle.com/cve/CVE-2014-0062.html" source="CVE"/>
        <reference ref_id="CVE-2014-0063" ref_url="http://linux.oracle.com/cve/CVE-2014-0063.html" source="CVE"/>
        <reference ref_id="CVE-2014-0064" ref_url="http://linux.oracle.com/cve/CVE-2014-0064.html" source="CVE"/>
        <reference ref_id="CVE-2014-0065" ref_url="http://linux.oracle.com/cve/CVE-2014-0065.html" source="CVE"/>
        <reference ref_id="CVE-2014-0066" ref_url="http://linux.oracle.com/cve/CVE-2014-0066.html" source="CVE"/>
        <description>PostgreSQL is an advanced object-relational database management system
(DBMS).
Multiple stack-based buffer overflow flaws were found in the date/time
implementation of PostgreSQL. An authenticated database user could provide
a specially crafted date/time value that, when processed, could cause
PostgreSQL to crash or, potentially, execute arbitrary code with the
permissions of the user running PostgreSQL. (CVE-2014-0063)
Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in various type input functions in PostgreSQL. An authenticated
database user could possibly use these flaws to crash PostgreSQL or,
potentially, execute arbitrary code with the permissions of the user
running PostgreSQL. (CVE-2014-0064)
Multiple potential buffer overflow flaws were found in PostgreSQL.
An authenticated database user could possibly use these flaws to crash
PostgreSQL or, potentially, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2014-0065)
It was found that granting an SQL role to a database user in a PostgreSQL
database without specifying the "ADMIN" option allowed the grantee to
remove other users from their granted role. An authenticated database user
could use this flaw to remove a user from an SQL role which they were
granted access to. (CVE-2014-0060)
A flaw was found in the validator functions provided by PostgreSQL's
procedural languages (PLs). An authenticated database user could possibly
use this flaw to escalate their privileges. (CVE-2014-0061)
A race condition was found in the way the CREATE INDEX command performed
multiple independent lookups of a table that had to be indexed. An
authenticated database user could possibly use this flaw to escalate their
privileges. (CVE-2014-0062)
It was found that the chkpass extension of PostgreSQL did not check the
return value of the crypt() function. An authenticated database user could
possibly use this flaw to crash PostgreSQL via a null pointer dereference.
(CVE-2014-0066)
Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Noah Misch as the original reporter of
CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the
original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as
the original reporters of CVE-2014-0065, Andres Freund as the original
reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original
reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the
original reporters of CVE-2014-0066.
These updated packages upgrade PostgreSQL to version 8.4.20, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:
http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
http://www.postgresql.org/docs/8.4/static/release-8-4-20.html
All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:28.851-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:37.142-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24493 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:25.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113342"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112768"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113485"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113256"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113662"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113627"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113378"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113697"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113496"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113704"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113398"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113676"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113756"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113440"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113706"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113604"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113665"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113265"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113474"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113747"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113761"/>
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24458" version="14" class="patch">
      <metadata>
        <title>ELSA-2014:0310: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0310-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0310.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)
Several information disclosure flaws were found in the way Firefox
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Firefox to crash. (CVE-2014-1497,
CVE-2014-1508, CVE-2014-1505)
A memory corruption flaw was found in the way Firefox rendered certain PDF
files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Firefox or, potentially, execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2014-1509)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.4.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.4.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:29.782-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:36.273-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24458 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:24.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113642"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113655"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24432" version="26" class="patch">
      <metadata>
        <title>ELSA-2014:0341: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2014:0341-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0341.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5595" ref_url="http://linux.oracle.com/cve/CVE-2012-5595.html" source="CVE"/>
        <reference ref_id="CVE-2012-5598" ref_url="http://linux.oracle.com/cve/CVE-2012-5598.html" source="CVE"/>
        <reference ref_id="CVE-2012-5599" ref_url="http://linux.oracle.com/cve/CVE-2012-5599.html" source="CVE"/>
        <reference ref_id="CVE-2012-5600" ref_url="http://linux.oracle.com/cve/CVE-2012-5600.html" source="CVE"/>
        <reference ref_id="CVE-2012-6056" ref_url="http://linux.oracle.com/cve/CVE-2012-6056.html" source="CVE"/>
        <reference ref_id="CVE-2012-6060" ref_url="http://linux.oracle.com/cve/CVE-2012-6060.html" source="CVE"/>
        <reference ref_id="CVE-2012-6061" ref_url="http://linux.oracle.com/cve/CVE-2012-6061.html" source="CVE"/>
        <reference ref_id="CVE-2012-6062" ref_url="http://linux.oracle.com/cve/CVE-2012-6062.html" source="CVE"/>
        <reference ref_id="CVE-2013-3557" ref_url="http://linux.oracle.com/cve/CVE-2013-3557.html" source="CVE"/>
        <reference ref_id="CVE-2013-3559" ref_url="http://linux.oracle.com/cve/CVE-2013-3559.html" source="CVE"/>
        <reference ref_id="CVE-2013-4081" ref_url="http://linux.oracle.com/cve/CVE-2013-4081.html" source="CVE"/>
        <reference ref_id="CVE-2013-4083" ref_url="http://linux.oracle.com/cve/CVE-2013-4083.html" source="CVE"/>
        <reference ref_id="CVE-2013-4927" ref_url="http://linux.oracle.com/cve/CVE-2013-4927.html" source="CVE"/>
        <reference ref_id="CVE-2013-4931" ref_url="http://linux.oracle.com/cve/CVE-2013-4931.html" source="CVE"/>
        <reference ref_id="CVE-2013-4932" ref_url="http://linux.oracle.com/cve/CVE-2013-4932.html" source="CVE"/>
        <reference ref_id="CVE-2013-4933" ref_url="http://linux.oracle.com/cve/CVE-2013-4933.html" source="CVE"/>
        <reference ref_id="CVE-2013-4934" ref_url="http://linux.oracle.com/cve/CVE-2013-4934.html" source="CVE"/>
        <reference ref_id="CVE-2013-4935" ref_url="http://linux.oracle.com/cve/CVE-2013-4935.html" source="CVE"/>
        <reference ref_id="CVE-2013-5721" ref_url="http://linux.oracle.com/cve/CVE-2013-5721.html" source="CVE"/>
        <reference ref_id="CVE-2013-7112" ref_url="http://linux.oracle.com/cve/CVE-2013-7112.html" source="CVE"/>
        <reference ref_id="CVE-2014-2281" ref_url="http://linux.oracle.com/cve/CVE-2014-2281.html" source="CVE"/>
        <reference ref_id="CVE-2014-2299" ref_url="http://linux.oracle.com/cve/CVE-2014-2299.html" source="CVE"/>
        <description>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.
Multiple flaws were found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark.
(CVE-2013-3559, CVE-2013-4083, CVE-2014-2281, CVE-2014-2299)
Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2012-5595, CVE-2012-5598, CVE-2012-5599,
CVE-2012-5600, CVE-2012-6056, CVE-2012-6060, CVE-2012-6061, CVE-2012-6062,
CVE-2013-3557, CVE-2013-4081, CVE-2013-4927, CVE-2013-4931, CVE-2013-4932,
CVE-2013-4933, CVE-2013-4934, CVE-2013-4935, CVE-2013-5721, CVE-2013-7112)
All Wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:47.141-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:34.838-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24432 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:24.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-6.el5_10" test_ref="oval:org.mitre.oval:tst:113605"/>
          <criterion comment="wireshark is earlier than 0:1.0.15-6.el5_10" test_ref="oval:org.mitre.oval:tst:112918"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24418" version="14" class="patch">
      <metadata>
        <title>ELSA-2014:0316: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0316-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0316.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)
Several information disclosure flaws were found in the way Thunderbird
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Thunderbird to crash.
(CVE-2014-1497, CVE-2014-1508, CVE-2014-1505)
A memory corruption flaw was found in the way Thunderbird rendered certain
PDF files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1509)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:28.104-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:34.637-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24418 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:23.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113726"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113759"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24411" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0412: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0412-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0412.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:37.606-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:36.766-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:13.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24411 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:35.541-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:16.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113800"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114265"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113633"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113954"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114254"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114101"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114315"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114056"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114311"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114166"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114159"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24349" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0448: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0448-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0448.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Firefox resolved hosts in
certain circumstances. An attacker could use this flaw to crash Firefox or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Firefox decoded JPEG
images. Loading a web page containing a specially crafted JPEG image could
cause Firefox to crash. (CVE-2014-1523)
A flaw was found in the way Firefox handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith, and Jesse
Schwartzentrube as the original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to this updated package, which contains
Firefox version 24.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:33.852-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:35.107-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:09.708-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24349 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:28.850-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:14.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114298"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114015"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24343" version="15" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0316: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0316-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0316.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)
Several information disclosure flaws were found in the way Thunderbird
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Thunderbird to crash.
(CVE-2014-1497, CVE-2014-1508, CVE-2014-1505)
A memory corruption flaw was found in the way Thunderbird rendered certain
PDF files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1509)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:39.553-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:33.177-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24343 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:23.090-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:03:26.450-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:03:26.450-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113543"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112954"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24331" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0369: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2014:0369-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0369.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6438" ref_url="http://linux.oracle.com/cve/CVE-2013-6438.html" source="CVE"/>
        <reference ref_id="CVE-2014-0098" ref_url="http://linux.oracle.com/cve/CVE-2014-0098.html" source="CVE"/>
        <description>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.
It was found that the mod_dav module did not correctly strip leading white
space from certain elements in a parsed XML. In certain httpd
configurations that use the mod_dav module (for example when using the
mod_dav_svn module), a remote attacker could send a specially crafted DAV
request that would cause the httpd child process to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
"apache" user. (CVE-2013-6438)
A buffer over-read flaw was found in the httpd mod_log_config module.
In configurations where cookie logging is enabled (on Red Hat Enterprise
Linux it is disabled by default), a remote attacker could use this flaw to
crash the httpd child process via an HTTP request with a malformed cookie
header. (CVE-2014-0098)
All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:40.222-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:32.828-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24331 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:22.857-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mod_ssl is earlier than 1:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:112721"/>
          <criterion comment="httpd is earlier than 0:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:113086"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:113609"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-85.el5_10" test_ref="oval:org.mitre.oval:tst:113484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24306" version="7" class="patch">
      <metadata>
        <title>ELSA-2014:0305: samba security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2014:0305-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0305.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0213" ref_url="http://linux.oracle.com/cve/CVE-2013-0213.html" source="CVE"/>
        <reference ref_id="CVE-2013-0214" ref_url="http://linux.oracle.com/cve/CVE-2013-0214.html" source="CVE"/>
        <reference ref_id="CVE-2013-4124" ref_url="http://linux.oracle.com/cve/CVE-2013-4124.html" source="CVE"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.
It was discovered that the Samba Web Administration Tool (SWAT) did not
protect against being opened in a web page frame. A remote attacker could
possibly use this flaw to conduct a clickjacking attack against SWAT users
or users with an active SWAT session. (CVE-2013-0213)
A flaw was found in the Cross-Site Request Forgery (CSRF) protection
mechanism implemented in SWAT. An attacker with the knowledge of a victim's
password could use this flaw to bypass CSRF protections and conduct a CSRF
attack against the victim SWAT user. (CVE-2013-0214)
An integer overflow flaw was found in the way Samba handled an Extended
Attribute (EA) list provided by a client. A malicious client could send a
specially crafted EA list that triggered an overflow, causing the server to
loop and reprocess the list using an excessive amount of memory.
(CVE-2013-4124)
Note: This issue did not affect the default configuration of the Samba
server.
Red Hat would like to thank the Samba project for reporting CVE-2013-0213
and CVE-2013-0214. Upstream acknowledges Jann Horn as the original reporter
of CVE-2013-0213 and CVE-2013-0214.
All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:45.667-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:32.207-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24306 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:22.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113533"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113159"/>
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113458"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:112674"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113347"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.40.el5_10" test_ref="oval:org.mitre.oval:tst:113269"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24289" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0206: openldap security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference ref_id="ELSA-2014:0206-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0206.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4449" ref_url="http://linux.oracle.com/cve/CVE-2013-4449.html" source="CVE"/>
        <description>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols used
to access and maintain distributed directory information services over an
IP network. The openldap package contains configuration files, libraries,
and documentation for OpenLDAP.
A denial of service flaw was found in the way the OpenLDAP server daemon
(slapd) performed reference counting when using the rwm (rewrite/remap)
overlay. A remote attacker able to query the OpenLDAP server could use this
flaw to crash the server by immediately unbinding from the server after
sending a search request. (CVE-2013-4449)
Red Hat would like to thank Michael Vishchers from Seven Principles AG for
reporting this issue.
All openldap users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:46.092-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:31.925-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24289 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:22.349-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openldap-devel is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:113219"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:113399"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:112586"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:113323"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:113549"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-27.el5_10" test_ref="oval:org.mitre.oval:tst:113321"/>
          <criterion comment="openldap is earlier than 0:2.3.43-27.el5_10" test_ref="oval:org.mitre.oval:tst:113546"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24265" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0322: net-snmp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>net-snmp</product>
        </affected>
        <reference ref_id="ELSA-2014:0322-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0322.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6151" ref_url="http://linux.oracle.com/cve/CVE-2012-6151.html" source="CVE"/>
        <reference ref_id="CVE-2014-2285" ref_url="http://linux.oracle.com/cve/CVE-2014-2285.html" source="CVE"/>
        <description>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.
A denial of service flaw was found in the way snmpd, the Net-SNMP daemon,
handled subagent timeouts. A remote attacker able to trigger a subagent
timeout could use this flaw to cause snmpd to loop infinitely or crash.
(CVE-2012-6151)
A denial of service flaw was found in the way the snmptrapd service, which
receives and logs SNMP trap messages, handled SNMP trap requests with an
empty community string when the Perl handler (provided by the net-snmp-perl
package) was enabled. A remote attacker could use this flaw to crash
snmptrapd by sending a trap request with an empty community string.
(CVE-2014-2285)
All net-snmp users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the snmpd and snmptrapd services will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:40.716-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:31.350-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24265 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:22.052-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="net-snmp-perl is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:112615"/>
          <criterion comment="net-snmp-utils is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:113507"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:113500"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:113034"/>
          <criterion comment="net-snmp is earlier than 1:5.3.2.2-22.el5_10.1" test_ref="oval:org.mitre.oval:tst:113499"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24255" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0247: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2014:0247-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0247.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-5138" ref_url="http://linux.oracle.com/cve/CVE-2009-5138.html" source="CVE"/>
        <reference ref_id="CVE-2014-0092" ref_url="http://linux.oracle.com/cve/CVE-2014-0092.html" source="CVE"/>
        <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).
It was discovered that GnuTLS did not correctly handle certain errors that
could occur during the verification of an X.509 certificate, causing it to
incorrectly report a successful verification. An attacker could use this
flaw to create a specially crafted certificate that could be accepted by
GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092)
A flaw was found in the way GnuTLS handled version 1 X.509 certificates.
An attacker able to obtain a version 1 certificate from a trusted
certificate authority could use this flaw to issue certificates for other
sites that would be accepted by GnuTLS as valid. (CVE-2009-5138)
The CVE-2014-0092 issue was discovered by Nikos Mavrogiannopoulos of the
Red Hat Security Technologies Team.
Users of GnuTLS are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the GnuTLS library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:43.503-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:30.932-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24255 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:21.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:113356"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:113351"/>
          <criterion comment="gnutls is earlier than 0:1.4.1-14.el5_10" test_ref="oval:org.mitre.oval:tst:112599"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24244" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0266: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2014:0266-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0266.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0106" ref_url="http://linux.oracle.com/cve/CVE-2014-0106.html" source="CVE"/>
        <description>Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:43.286-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:30.738-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:13.284-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24244 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:20.268-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:11.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-29.el5_10" test_ref="oval:org.mitre.oval:tst:112793"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24229" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0496: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0496-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0496.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0510" ref_url="http://linux.oracle.com/cve/CVE-2014-0510.html" source="CVE"/>
        <reference ref_id="CVE-2014-0516" ref_url="http://linux.oracle.com/cve/CVE-2014-0516.html" source="CVE"/>
        <reference ref_id="CVE-2014-0517" ref_url="http://linux.oracle.com/cve/CVE-2014-0517.html" source="CVE"/>
        <reference ref_id="CVE-2014-0518" ref_url="http://linux.oracle.com/cve/CVE-2014-0518.html" source="CVE"/>
        <reference ref_id="CVE-2014-0519" ref_url="http://linux.oracle.com/cve/CVE-2014-0519.html" source="CVE"/>
        <reference ref_id="CVE-2014-0520" ref_url="http://linux.oracle.com/cve/CVE-2014-0520.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-14,
listed in the References section.
Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0510, CVE-2014-0517, CVE-2014-0518, CVE-2014-0519,
CVE-2014-0520)
A flaw in flash-plugin could allow an attacker to bypass the same-origin
policy. (CVE-2014-0516)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.359.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:52.063-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24229 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:19.135-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:38.051-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el5" test_ref="oval:org.mitre.oval:tst:115417"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el6" test_ref="oval:org.mitre.oval:tst:115395"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24206" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0348: xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xalan-j2</product>
        </affected>
        <reference ref_id="ELSA-2014:0348-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0348.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0107" ref_url="http://linux.oracle.com/cve/CVE-2014-0107.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:44.537-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:30.136-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:12.606-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24206 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.085-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:02:55.186-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:02:55.186-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113588"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112926"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113312"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113423"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112920"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113497"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113407"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:112946"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113514"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113602"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24198" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1452: vino security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference ref_id="ELSA-2013:1452-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1452.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5745" ref_url="http://linux.oracle.com/cve/CVE-2013-5745.html" source="CVE"/>
        <description>The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:02.040-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.667-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:29.908-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24198 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:54.163-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:21.029-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="vino is earlier than 0:2.28.1-9.el6_4" test_ref="oval:org.mitre.oval:tst:112262"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="vino is earlier than 0:2.13.5-10.el5_10" test_ref="oval:org.mitre.oval:tst:112485"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24196" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1869: pixman security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference ref_id="ELSA-2013:1869-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1869.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6425" ref_url="http://linux.oracle.com/cve/CVE-2013-6425.html" source="CVE"/>
        <description>Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:07.883-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.592-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:29.801-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24196 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:47.464-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:112381"/>
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:112642"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:112846"/>
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:112654"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24180" version="57" class="patch">
      <metadata>
        <title>ELSA-2014:0097: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0097-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0097.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:38.540-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:50.930-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:27.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24180 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.464-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:19.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112353"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112681"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112877"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112874"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112840"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112230"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112495"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112691"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112610"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24179" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1268: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1268-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1268.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1718" ref_url="http://linux.oracle.com/cve/CVE-2013-1718.html" source="CVE"/>
        <reference ref_id="CVE-2013-1722" ref_url="http://linux.oracle.com/cve/CVE-2013-1722.html" source="CVE"/>
        <reference ref_id="CVE-2013-1725" ref_url="http://linux.oracle.com/cve/CVE-2013-1725.html" source="CVE"/>
        <reference ref_id="CVE-2013-1730" ref_url="http://linux.oracle.com/cve/CVE-2013-1730.html" source="CVE"/>
        <reference ref_id="CVE-2013-1732" ref_url="http://linux.oracle.com/cve/CVE-2013-1732.html" source="CVE"/>
        <reference ref_id="CVE-2013-1735" ref_url="http://linux.oracle.com/cve/CVE-2013-1735.html" source="CVE"/>
        <reference ref_id="CVE-2013-1736" ref_url="http://linux.oracle.com/cve/CVE-2013-1736.html" source="CVE"/>
        <reference ref_id="CVE-2013-1737" ref_url="http://linux.oracle.com/cve/CVE-2013-1737.html" source="CVE"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:10.643-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:50.724-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:27.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24179 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.803-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:19.080-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112337"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112120"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112032"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:112254"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:112294"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:111812"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24175" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0449: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0449-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0449.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Thunderbird resolved hosts in
certain circumstances. An attacker could use this flaw to crash Thunderbird
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Thunderbird decoded JPEG
images. Loading an email or a web page containing a specially crafted JPEG
image could cause Thunderbird to crash. (CVE-2014-1523)
A flaw was found in the way Thunderbird handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith and Jesse
Schwartzentrube as the original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:36.010-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:30.114-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:02.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24175 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:15.450-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:01:49.627-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:01:49.627-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113715"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114077"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24167" version="57" class="patch">
      <metadata>
        <title>ELSA-2014:0139: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2014:0139-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0139.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6152" ref_url="http://linux.oracle.com/cve/CVE-2012-6152.html" source="CVE"/>
        <reference ref_id="CVE-2013-6477" ref_url="http://linux.oracle.com/cve/CVE-2013-6477.html" source="CVE"/>
        <reference ref_id="CVE-2013-6478" ref_url="http://linux.oracle.com/cve/CVE-2013-6478.html" source="CVE"/>
        <reference ref_id="CVE-2013-6479" ref_url="http://linux.oracle.com/cve/CVE-2013-6479.html" source="CVE"/>
        <reference ref_id="CVE-2013-6481" ref_url="http://linux.oracle.com/cve/CVE-2013-6481.html" source="CVE"/>
        <reference ref_id="CVE-2013-6482" ref_url="http://linux.oracle.com/cve/CVE-2013-6482.html" source="CVE"/>
        <reference ref_id="CVE-2013-6483" ref_url="http://linux.oracle.com/cve/CVE-2013-6483.html" source="CVE"/>
        <reference ref_id="CVE-2013-6484" ref_url="http://linux.oracle.com/cve/CVE-2013-6484.html" source="CVE"/>
        <reference ref_id="CVE-2013-6485" ref_url="http://linux.oracle.com/cve/CVE-2013-6485.html" source="CVE"/>
        <reference ref_id="CVE-2013-6487" ref_url="http://linux.oracle.com/cve/CVE-2013-6487.html" source="CVE"/>
        <reference ref_id="CVE-2013-6489" ref_url="http://linux.oracle.com/cve/CVE-2013-6489.html" source="CVE"/>
        <reference ref_id="CVE-2013-6490" ref_url="http://linux.oracle.com/cve/CVE-2013-6490.html" source="CVE"/>
        <reference ref_id="CVE-2014-0020" ref_url="http://linux.oracle.com/cve/CVE-2014-0020.html" source="CVE"/>
        <description>The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:33.965-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:49.508-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:25.035-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24167 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:52.422-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:17.855-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112723"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112604"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112554"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112410"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112543"/>
            <criterion comment="finch is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112819"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112783"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112864"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112308"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112276"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112667"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112333"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112136"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112628"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112811"/>
            <criterion comment="finch is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112511"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112474"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112528"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112788"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24156" version="29" class="patch">
      <metadata>
        <title>ELSA-2014:0133: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0133-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0133.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:37.606-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.982-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:24.426-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24156 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.146-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:17.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:112631"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:112688"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24153" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1813: php53 and php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:1813-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1813.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6420" ref_url="http://linux.oracle.com/cve/CVE-2013-6420.html" source="CVE"/>
        <description>The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:10.758-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.739-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:24.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24153 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.116-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:17.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-intl is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112590"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112616"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:111824"/>
            <criterion comment="php53 is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112245"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112079"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112702"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:111715"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112638"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112690"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112598"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112050"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112542"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112235"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112671"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112480"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112659"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112467"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112660"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112007"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112152"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112687"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112648"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:111806"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112597"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112518"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112585"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112492"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112208"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112682"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112150"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112626"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112668"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112614"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112005"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112073"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112142"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112727"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112728"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112365"/>
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112675"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112775"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112268"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112541"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112374"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112636"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112352"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112361"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112486"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24148" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0447: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0447-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0447.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0515" ref_url="http://linux.oracle.com/cve/CVE-2014-0515.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed
in the References section.
A flaw was found in the way flash-plugin displayed certain SWF content. An
attacker could use this flaw to create a specially crafted SWF file that
would cause flash-plugin to crash or, potentially, execute arbitrary code
when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0515)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.356.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:45.366-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:29.732-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:02.537-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24148 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:20.421-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:10.056-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" test_ref="oval:org.mitre.oval:tst:113934"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" test_ref="oval:org.mitre.oval:tst:113615"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24142" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1426: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2013:1426-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1426.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4396" ref_url="http://linux.oracle.com/cve/CVE-2013-4396.html" source="CVE"/>
        <description>Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:03.802-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.378-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:23.711-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24142 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.503-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:16.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112399"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112441"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112153"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112380"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112061"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:111496"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112135"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112286"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112398"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112388"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:111965"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112179"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112392"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112141"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112243"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112363"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112314"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24139" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1480: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1480-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1480.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a CANVAS element, a mozTextStyle attribute, and an onresize event.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:11.210-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.242-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:23.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24139 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.661-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:16.710-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:111654"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112407"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24124" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1049: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:1049-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1049.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4113" ref_url="http://linux.oracle.com/cve/CVE-2013-4113.html" source="CVE"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:12.433-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.089-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:22.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24124 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:49.096-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112093"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112299"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112199"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111321"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112130"/>
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111823"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111298"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112216"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112193"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112203"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112066"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112161"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112042"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111608"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111650"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111984"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112258"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112251"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111760"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112017"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112283"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112234"/>
            <criterion comment="php-common is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112119"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111889"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112198"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112242"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111666"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-xml is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112038"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112160"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112320"/>
            <criterion comment="php is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111832"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111787"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112226"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111343"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112080"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112134"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112253"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111928"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112312"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111712"/>
            <criterion comment="php-common is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111879"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112006"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112309"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111332"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112298"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112302"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24123" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0018: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference ref_id="ELSA-2014:0018-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0018.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6462" ref_url="http://linux.oracle.com/cve/CVE-2013-6462.html" source="CVE"/>
        <description>Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:35.638-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.017-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.953-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24123 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.086-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:112770"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:112797"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:112849"/>
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:111869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24121" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1409: xinetd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference ref_id="ELSA-2013:1409-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1409.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4342" ref_url="http://linux.oracle.com/cve/CVE-2013-4342.html" source="CVE"/>
        <description>xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:03.970-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.879-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24121 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.411-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="xinetd is earlier than 2:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:112450"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xinetd is earlier than 2:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:112432"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24118" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1476: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1476-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1476.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5590" ref_url="http://linux.oracle.com/cve/CVE-2013-5590.html" source="CVE"/>
        <reference ref_id="CVE-2013-5595" ref_url="http://linux.oracle.com/cve/CVE-2013-5595.html" source="CVE"/>
        <reference ref_id="CVE-2013-5597" ref_url="http://linux.oracle.com/cve/CVE-2013-5597.html" source="CVE"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <reference ref_id="CVE-2013-5600" ref_url="http://linux.oracle.com/cve/CVE-2013-5600.html" source="CVE"/>
        <reference ref_id="CVE-2013-5601" ref_url="http://linux.oracle.com/cve/CVE-2013-5601.html" source="CVE"/>
        <reference ref_id="CVE-2013-5602" ref_url="http://linux.oracle.com/cve/CVE-2013-5602.html" source="CVE"/>
        <reference ref_id="CVE-2013-5604" ref_url="http://linux.oracle.com/cve/CVE-2013-5604.html" source="CVE"/>
        <description>The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:50:59.155-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.496-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.213-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24118 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:50.785-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:112207"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:112455"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:112499"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112508"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112465"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112144"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24116" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0815: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:0815-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0815.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3499" ref_url="http://linux.oracle.com/cve/CVE-2012-3499.html" source="CVE"/>
        <reference ref_id="CVE-2012-4558" ref_url="http://linux.oracle.com/cve/CVE-2012-4558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1862" ref_url="http://linux.oracle.com/cve/CVE-2013-1862.html" source="CVE"/>
        <description>mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:42.975-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.389-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:20.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24116 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:49.752-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111993"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111468"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111963"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111612"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111458"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:112026"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:111973"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:111919"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:111987"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24114" version="12" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0211: postgresql84 and postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2014:0211-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0211.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0060" ref_url="http://linux.oracle.com/cve/CVE-2014-0060.html" source="CVE"/>
        <reference ref_id="CVE-2014-0061" ref_url="http://linux.oracle.com/cve/CVE-2014-0061.html" source="CVE"/>
        <reference ref_id="CVE-2014-0062" ref_url="http://linux.oracle.com/cve/CVE-2014-0062.html" source="CVE"/>
        <reference ref_id="CVE-2014-0063" ref_url="http://linux.oracle.com/cve/CVE-2014-0063.html" source="CVE"/>
        <reference ref_id="CVE-2014-0064" ref_url="http://linux.oracle.com/cve/CVE-2014-0064.html" source="CVE"/>
        <reference ref_id="CVE-2014-0065" ref_url="http://linux.oracle.com/cve/CVE-2014-0065.html" source="CVE"/>
        <reference ref_id="CVE-2014-0066" ref_url="http://linux.oracle.com/cve/CVE-2014-0066.html" source="CVE"/>
        <description>The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:44.038-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:20.467-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:11.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24114 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:22.802-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:01:15.194-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:01:15.194-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113123"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113254"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113358"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113516"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112870"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113563"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112971"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113181"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113427"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113343"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113564"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113541"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112895"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113331"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113425"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113534"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113479"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112901"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113349"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113420"/>
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113522"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24091" version="29" class="patch">
      <metadata>
        <title>ELSA-2013:1142: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1142-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-1142.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1701" ref_url="http://linux.oracle.com/cve/CVE-2013-1701.html" source="CVE"/>
        <reference ref_id="CVE-2013-1709" ref_url="http://linux.oracle.com/cve/CVE-2013-1709.html" source="CVE"/>
        <reference ref_id="CVE-2013-1710" ref_url="http://linux.oracle.com/cve/CVE-2013-1710.html" source="CVE"/>
        <reference ref_id="CVE-2013-1713" ref_url="http://linux.oracle.com/cve/CVE-2013-1713.html" source="CVE"/>
        <reference ref_id="CVE-2013-1714" ref_url="http://linux.oracle.com/cve/CVE-2013-1714.html" source="CVE"/>
        <reference ref_id="CVE-2013-1717" ref_url="http://linux.oracle.com/cve/CVE-2013-1717.html" source="CVE"/>
        <description>Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:59.502-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.788-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:17.459-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24091 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.905-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.611-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el6_4" test_ref="oval:org.mitre.oval:tst:111373"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el5_9" test_ref="oval:org.mitre.oval:tst:112341"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24088" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1868: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2013:1868-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1868.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6424" ref_url="http://linux.oracle.com/cve/CVE-2013-6424.html" source="CVE"/>
        <description>Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:09.857-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.685-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:17.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24088 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.655-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112278"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112564"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112670"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112420"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112582"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:111858"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112739"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112730"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112750"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112545"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112704"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112785"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112072"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112562"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112822"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112461"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112839"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24083" version="29" class="patch">
      <metadata>
        <title>ELSA-2013:1140: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1140-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1140.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1701" ref_url="http://linux.oracle.com/cve/CVE-2013-1701.html" source="CVE"/>
        <reference ref_id="CVE-2013-1709" ref_url="http://linux.oracle.com/cve/CVE-2013-1709.html" source="CVE"/>
        <reference ref_id="CVE-2013-1710" ref_url="http://linux.oracle.com/cve/CVE-2013-1710.html" source="CVE"/>
        <reference ref_id="CVE-2013-1713" ref_url="http://linux.oracle.com/cve/CVE-2013-1713.html" source="CVE"/>
        <reference ref_id="CVE-2013-1714" ref_url="http://linux.oracle.com/cve/CVE-2013-1714.html" source="CVE"/>
        <reference ref_id="CVE-2013-1717" ref_url="http://linux.oracle.com/cve/CVE-2013-1717.html" source="CVE"/>
        <description>Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:09.410-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.166-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:16.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24083 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.276-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el6_4" test_ref="oval:org.mitre.oval:tst:111950"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:111913"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:112109"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el5_9" test_ref="oval:org.mitre.oval:tst:112304"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:112338"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:112012"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24069" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0646: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2013:0646-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0646.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0272" ref_url="http://linux.oracle.com/cve/CVE-2013-0272.html" source="CVE"/>
        <reference ref_id="CVE-2013-0273" ref_url="http://linux.oracle.com/cve/CVE-2013-0273.html" source="CVE"/>
        <reference ref_id="CVE-2013-0274" ref_url="http://linux.oracle.com/cve/CVE-2013-0274.html" source="CVE"/>
        <description>upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:34.956-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:43.394-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:15.250-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24069 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:07.121-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.002-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111551"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111094"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111483"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111846"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111055"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111837"/>
            <criterion comment="finch is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111814"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111293"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111505"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111594"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111805"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111667"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111758"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111794"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111605"/>
            <criterion comment="finch is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111535"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111227"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111752"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111769"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24063" version="93" class="patch">
      <metadata>
        <title>ELSA-2013:0247: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0247-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0247.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0429" ref_url="http://linux.oracle.com/cve/CVE-2013-0429.html" source="CVE"/>
        <reference ref_id="CVE-2013-0431" ref_url="http://linux.oracle.com/cve/CVE-2013-0431.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0435" ref_url="http://linux.oracle.com/cve/CVE-2013-0435.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0441" ref_url="http://linux.oracle.com/cve/CVE-2013-0441.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0444" ref_url="http://linux.oracle.com/cve/CVE-2013-0444.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-1475" ref_url="http://linux.oracle.com/cve/CVE-2013-1475.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.	 NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:29.312-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.863-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:14.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24063 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:58.114-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:10.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:110864"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:111489"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:111500"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:110519"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:110987"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111372"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111425"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111089"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111015"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111288"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24061" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0272: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0272-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0272.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0775" ref_url="http://linux.oracle.com/cve/CVE-2013-0775.html" source="CVE"/>
        <reference ref_id="CVE-2013-0776" ref_url="http://linux.oracle.com/cve/CVE-2013-0776.html" source="CVE"/>
        <reference ref_id="CVE-2013-0780" ref_url="http://linux.oracle.com/cve/CVE-2013-0780.html" source="CVE"/>
        <reference ref_id="CVE-2013-0782" ref_url="http://linux.oracle.com/cve/CVE-2013-0782.html" source="CVE"/>
        <reference ref_id="CVE-2013-0783" ref_url="http://linux.oracle.com/cve/CVE-2013-0783.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:28.157-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.647-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:13.871-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24061 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.137-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:10.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:110654"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111310"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24051" version="85" class="patch">
      <metadata>
        <title>ELSA-2013:0770: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0770-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0770.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1488" ref_url="http://linux.oracle.com/cve/CVE-2013-1488.html" source="CVE"/>
        <reference ref_id="CVE-2013-1518" ref_url="http://linux.oracle.com/cve/CVE-2013-1518.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2415" ref_url="http://linux.oracle.com/cve/CVE-2013-2415.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2421" ref_url="http://linux.oracle.com/cve/CVE-2013-2421.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2426" ref_url="http://linux.oracle.com/cve/CVE-2013-2426.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2431" ref_url="http://linux.oracle.com/cve/CVE-2013-2431.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to bypassing the Java sandbox using "method handle intrinsic frames."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:34.114-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:41.704-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:12.163-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24051 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:06.222-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:09.129-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:112023"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111348"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111917"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111717"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111985"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111777"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111922"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111988"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:112031"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111953"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24050" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1475: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2013:1475-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1475.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0255" ref_url="http://linux.oracle.com/cve/CVE-2013-0255.html" source="CVE"/>
        <reference ref_id="CVE-2013-1000" ref_url="http://linux.oracle.com/cve/CVE-2013-1000.html" source="CVE"/>
        <description>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:00.891-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:41.540-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:11.980-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24050 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.512-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:08.967-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112509"/>
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112297"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112446"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112496"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:111878"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112428"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112162"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112139"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112366"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112505"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112348"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112503"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112500"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112313"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:111939"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112279"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112421"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112448"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112359"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112425"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112510"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24043" version="105" class="patch">
      <metadata>
        <title>ELSA-2013:1014: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1014-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1014.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.	NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:12.976-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:40.651-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:10.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24043 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:04.758-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:08.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112116"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112147"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112248"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:111991"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112049"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:111836"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112123"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112266"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112263"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112211"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24042" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0448: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0448-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0448.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Firefox resolved hosts in
certain circumstances. An attacker could use this flaw to crash Firefox or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Firefox decoded JPEG
images. Loading a web page containing a specially crafted JPEG image could
cause Firefox to crash. (CVE-2014-1523)
A flaw was found in the way Firefox handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith, and Jesse
Schwartzentrube as the original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to this updated package, which contains
Firefox version 24.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:38.968-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:27.594-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:01.461-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24042 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:30.510-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:59:29.932-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:59:29.932-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114191"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114123"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24014" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0820: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0820-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0820.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0801" ref_url="http://linux.oracle.com/cve/CVE-2013-0801.html" source="CVE"/>
        <reference ref_id="CVE-2013-1670" ref_url="http://linux.oracle.com/cve/CVE-2013-1670.html" source="CVE"/>
        <reference ref_id="CVE-2013-1674" ref_url="http://linux.oracle.com/cve/CVE-2013-1674.html" source="CVE"/>
        <reference ref_id="CVE-2013-1675" ref_url="http://linux.oracle.com/cve/CVE-2013-1675.html" source="CVE"/>
        <reference ref_id="CVE-2013-1676" ref_url="http://linux.oracle.com/cve/CVE-2013-1676.html" source="CVE"/>
        <reference ref_id="CVE-2013-1677" ref_url="http://linux.oracle.com/cve/CVE-2013-1677.html" source="CVE"/>
        <reference ref_id="CVE-2013-1678" ref_url="http://linux.oracle.com/cve/CVE-2013-1678.html" source="CVE"/>
        <reference ref_id="CVE-2013-1679" ref_url="http://linux.oracle.com/cve/CVE-2013-1679.html" source="CVE"/>
        <reference ref_id="CVE-2013-1680" ref_url="http://linux.oracle.com/cve/CVE-2013-1680.html" source="CVE"/>
        <reference ref_id="CVE-2013-1681" ref_url="http://linux.oracle.com/cve/CVE-2013-1681.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:47.684-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.127-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:05.563-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24014 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.435-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:05.020-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:17.0.6-1.el6_4" test_ref="oval:org.mitre.oval:tst:111992"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:111842"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:111931"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:111861"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:111921"/>
            <criterion comment="firefox is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:111902"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24005" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1457: libgcrypt security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference ref_id="ELSA-2013:1457-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1457.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4242" ref_url="http://linux.oracle.com/cve/CVE-2013-4242.html" source="CVE"/>
        <description>GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:09.491-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:36.695-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:02.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24005 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:08.339-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:03.054-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:112453"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:112513"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:112393"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:112369"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23998" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0250: elinks security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>elinks</product>
        </affected>
        <reference ref_id="ELSA-2013:0250-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0250.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4545" ref_url="http://linux.oracle.com/cve/CVE-2012-4545.html" source="CVE"/>
        <description>The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:28.530-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:36.337-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:02.398-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23998 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.808-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:02.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:111438"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:111328"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23994" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0447: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0447-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0447.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0515" ref_url="http://linux.oracle.com/cve/CVE-2014-0515.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed
in the References section.
A flaw was found in the way flash-plugin displayed certain SWF content. An
attacker could use this flaw to create a specially crafted SWF file that
would cause flash-plugin to crash or, potentially, execute arbitrary code
when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0515)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.356.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:30.556-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:27.055-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:00.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23994 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:21.145-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:58:55.950-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:58:55.950-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" test_ref="oval:org.mitre.oval:tst:114242"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" test_ref="oval:org.mitre.oval:tst:113355"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23987" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1090: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2013:1090-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1090.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4073" ref_url="http://linux.oracle.com/cve/CVE-2013-4073.html" source="CVE"/>
        <description>The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:59.134-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.538-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:01.235-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23987 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.883-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:01.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112277"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112081"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112014"/>
            <criterion comment="ruby-static is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112238"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112063"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112339"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112204"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112301"/>
            <criterion comment="ruby is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:111946"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112265"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112317"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112321"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:111682"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:111898"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112008"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112166"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112075"/>
            <criterion comment="ruby is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112281"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23985" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0408: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0408-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0408.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.
An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)
Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)
Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)
Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)
Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)
It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)
It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)
It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)
An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)
This update also fixes the following bug:
* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)
All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:36.715-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:25.405-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:59.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23985 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:28.620-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:05.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113857"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114138"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114246"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113249"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113792"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114001"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113931"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113677"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114214"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113692"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23978" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0696: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0696-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0696.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0788" ref_url="http://linux.oracle.com/cve/CVE-2013-0788.html" source="CVE"/>
        <reference ref_id="CVE-2013-0793" ref_url="http://linux.oracle.com/cve/CVE-2013-0793.html" source="CVE"/>
        <reference ref_id="CVE-2013-0795" ref_url="http://linux.oracle.com/cve/CVE-2013-0795.html" source="CVE"/>
        <reference ref_id="CVE-2013-0796" ref_url="http://linux.oracle.com/cve/CVE-2013-0796.html" source="CVE"/>
        <reference ref_id="CVE-2013-0800" ref_url="http://linux.oracle.com/cve/CVE-2013-0800.html" source="CVE"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:51.997-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.063-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:00.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23978 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:58.375-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111949"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111603"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111739"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111739"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111737"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111662"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111695"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23976" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0580: cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference ref_id="ELSA-2013:0580-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0580.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5519" ref_url="http://linux.oracle.com/cve/CVE-2012-5519.html" source="CVE"/>
        <description>CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:36.483-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.974-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:00.094-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23976 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.934-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cups-php is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111747"/>
            <criterion comment="cups-lpd is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111619"/>
            <criterion comment="cups-devel is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111697"/>
            <criterion comment="cups is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111708"/>
            <criterion comment="cups-libs is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111480"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cups-devel is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111540"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111668"/>
            <criterion comment="cups is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111614"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111702"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23972" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0668: boost security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>boost</product>
        </affected>
        <reference ref_id="ELSA-2013:0668-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0668.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2677" ref_url="http://linux.oracle.com/cve/CVE-2012-2677.html" source="CVE"/>
        <description>Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:40.421-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.663-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:59.685-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23972 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:07.632-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="boost-graph-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111706"/>
            <criterion comment="boost-graph-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111868"/>
            <criterion comment="boost-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111389"/>
            <criterion comment="boost-test is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111409"/>
            <criterion comment="boost-graph is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111847"/>
            <criterion comment="boost is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111610"/>
            <criterion comment="boost-mpich2-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111833"/>
            <criterion comment="boost-wave is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111783"/>
            <criterion comment="boost-filesystem is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111881"/>
            <criterion comment="boost-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111693"/>
            <criterion comment="boost-thread is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111394"/>
            <criterion comment="boost-mpich2-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111841"/>
            <criterion comment="boost-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111647"/>
            <criterion comment="boost-static is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111294"/>
            <criterion comment="boost-doc is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111813"/>
            <criterion comment="boost-regex is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111374"/>
            <criterion comment="boost-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111642"/>
            <criterion comment="boost-openmpi-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:110890"/>
            <criterion comment="boost-serialization is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111738"/>
            <criterion comment="boost-system is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111817"/>
            <criterion comment="boost-iostreams is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111864"/>
            <criterion comment="boost-signals is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:110896"/>
            <criterion comment="boost-program-options is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111000"/>
            <criterion comment="boost-openmpi-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111883"/>
            <criterion comment="boost-date-time is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111743"/>
            <criterion comment="boost-math is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111572"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="boost is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:111877"/>
            <criterion comment="boost-doc is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:111822"/>
            <criterion comment="boost-devel is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:111792"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23971" version="101" class="patch">
      <metadata>
        <title>ELSA-2012:1210: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1210-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1210.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1970" ref_url="http://linux.oracle.com/cve/CVE-2012-1970.html" source="CVE"/>
        <reference ref_id="CVE-2012-1972" ref_url="http://linux.oracle.com/cve/CVE-2012-1972.html" source="CVE"/>
        <reference ref_id="CVE-2012-1973" ref_url="http://linux.oracle.com/cve/CVE-2012-1973.html" source="CVE"/>
        <reference ref_id="CVE-2012-1974" ref_url="http://linux.oracle.com/cve/CVE-2012-1974.html" source="CVE"/>
        <reference ref_id="CVE-2012-1975" ref_url="http://linux.oracle.com/cve/CVE-2012-1975.html" source="CVE"/>
        <reference ref_id="CVE-2012-1976" ref_url="http://linux.oracle.com/cve/CVE-2012-1976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3956" ref_url="http://linux.oracle.com/cve/CVE-2012-3956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3957" ref_url="http://linux.oracle.com/cve/CVE-2012-3957.html" source="CVE"/>
        <reference ref_id="CVE-2012-3958" ref_url="http://linux.oracle.com/cve/CVE-2012-3958.html" source="CVE"/>
        <reference ref_id="CVE-2012-3959" ref_url="http://linux.oracle.com/cve/CVE-2012-3959.html" source="CVE"/>
        <reference ref_id="CVE-2012-3960" ref_url="http://linux.oracle.com/cve/CVE-2012-3960.html" source="CVE"/>
        <reference ref_id="CVE-2012-3961" ref_url="http://linux.oracle.com/cve/CVE-2012-3961.html" source="CVE"/>
        <reference ref_id="CVE-2012-3962" ref_url="http://linux.oracle.com/cve/CVE-2012-3962.html" source="CVE"/>
        <reference ref_id="CVE-2012-3963" ref_url="http://linux.oracle.com/cve/CVE-2012-3963.html" source="CVE"/>
        <reference ref_id="CVE-2012-3964" ref_url="http://linux.oracle.com/cve/CVE-2012-3964.html" source="CVE"/>
        <reference ref_id="CVE-2012-3966" ref_url="http://linux.oracle.com/cve/CVE-2012-3966.html" source="CVE"/>
        <reference ref_id="CVE-2012-3967" ref_url="http://linux.oracle.com/cve/CVE-2012-3967.html" source="CVE"/>
        <reference ref_id="CVE-2012-3968" ref_url="http://linux.oracle.com/cve/CVE-2012-3968.html" source="CVE"/>
        <reference ref_id="CVE-2012-3969" ref_url="http://linux.oracle.com/cve/CVE-2012-3969.html" source="CVE"/>
        <reference ref_id="CVE-2012-3970" ref_url="http://linux.oracle.com/cve/CVE-2012-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-3972" ref_url="http://linux.oracle.com/cve/CVE-2012-3972.html" source="CVE"/>
        <reference ref_id="CVE-2012-3976" ref_url="http://linux.oracle.com/cve/CVE-2012-3976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3978" ref_url="http://linux.oracle.com/cve/CVE-2012-3978.html" source="CVE"/>
        <reference ref_id="CVE-2012-3980" ref_url="http://linux.oracle.com/cve/CVE-2012-3980.html" source="CVE"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:41.132-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.101-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:58.750-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23971 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:03.794-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:59.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:110728"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:110757"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:110810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110831"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110952"/>
            <criterion comment="firefox is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110856"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23968" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0408: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0408-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0408.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.
An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)
Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)
Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)
Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)
Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)
It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)
It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)
It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)
An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)
This update also fixes the following bug:
* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)
All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:30.912-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:23.829-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:58.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23968 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:17.449-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:58:19.309-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:58:19.309-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114070"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113559"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114258"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114161"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113996"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113773"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114185"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113325"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114225"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114194"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23965" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0581: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2013:0581-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0581.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0338" ref_url="http://linux.oracle.com/cve/CVE-2013-0338.html" source="CVE"/>
        <description>libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:42.022-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.868-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:56.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23965 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:30.946-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:57:20.879-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:57:20.879-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111466"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111687"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111677"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111615"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:111525"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:111492"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:111128"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23962" version="33" class="patch">
      <metadata>
        <title>ELSA-2012:1255: libexif security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libexif</product>
        </affected>
        <reference ref_id="ELSA-2012:1255-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1255.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2812" ref_url="http://linux.oracle.com/cve/CVE-2012-2812.html" source="CVE"/>
        <reference ref_id="CVE-2012-2813" ref_url="http://linux.oracle.com/cve/CVE-2012-2813.html" source="CVE"/>
        <reference ref_id="CVE-2012-2814" ref_url="http://linux.oracle.com/cve/CVE-2012-2814.html" source="CVE"/>
        <reference ref_id="CVE-2012-2836" ref_url="http://linux.oracle.com/cve/CVE-2012-2836.html" source="CVE"/>
        <reference ref_id="CVE-2012-2837" ref_url="http://linux.oracle.com/cve/CVE-2012-2837.html" source="CVE"/>
        <reference ref_id="CVE-2012-2840" ref_url="http://linux.oracle.com/cve/CVE-2012-2840.html" source="CVE"/>
        <reference ref_id="CVE-2012-2841" ref_url="http://linux.oracle.com/cve/CVE-2012-2841.html" source="CVE"/>
        <description>Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:37.640-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.681-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:56.064-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23962 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.671-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:110958"/>
            <criterion comment="libexif is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:110938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:110821"/>
            <criterion comment="libexif is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:110400"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23961" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1779: mod_nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>mod_nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1779-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1779.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4566" ref_url="http://linux.oracle.com/cve/CVE-2013-4566.html" source="CVE"/>
        <description>mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:50:58.658-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.610-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:55.962-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23961 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:43.072-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="mod_nss is earlier than 0:1.0.8-8.el5_10" test_ref="oval:org.mitre.oval:tst:112632"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="mod_nss is earlier than 0:1.0.8-19.el6_5" test_ref="oval:org.mitre.oval:tst:112370"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23959" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1413: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1413-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1413.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4194" ref_url="http://linux.oracle.com/cve/CVE-2012-4194.html" source="CVE"/>
        <reference ref_id="CVE-2012-4195" ref_url="http://linux.oracle.com/cve/CVE-2012-4195.html" source="CVE"/>
        <reference ref_id="CVE-2012-4196" ref_url="http://linux.oracle.com/cve/CVE-2012-4196.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:11.727-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.393-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:55.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23959 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.873-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:111070"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:111057"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23952" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1362: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1362-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1362.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4193" ref_url="http://linux.oracle.com/cve/CVE-2012-4193.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:04.034-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.683-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.306-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23952 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.769-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:111270"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:110601"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23950" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0771: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0771-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0771.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1944" ref_url="http://linux.oracle.com/cve/CVE-2013-1944.html" source="CVE"/>
        <description>The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:52.421-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.615-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.196-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23950 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.829-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.323-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:111910"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:111775"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:111053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:111930"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:112003"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23949" version="109" class="patch">
      <metadata>
        <title>ELSA-2013:1505: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1505-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1505.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:14.639-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.079-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:53.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23949 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.325-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:55.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112311"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112324"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112408"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112292"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:111781"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112373"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112018"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112336"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112155"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112389"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23948" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0697: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0697-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0697.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0788" ref_url="http://linux.oracle.com/cve/CVE-2013-0788.html" source="CVE"/>
        <reference ref_id="CVE-2013-0793" ref_url="http://linux.oracle.com/cve/CVE-2013-0793.html" source="CVE"/>
        <reference ref_id="CVE-2013-0795" ref_url="http://linux.oracle.com/cve/CVE-2013-0795.html" source="CVE"/>
        <reference ref_id="CVE-2013-0796" ref_url="http://linux.oracle.com/cve/CVE-2013-0796.html" source="CVE"/>
        <reference ref_id="CVE-2013-0800" ref_url="http://linux.oracle.com/cve/CVE-2013-0800.html" source="CVE"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:41.925-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.909-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:52.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23948 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.310-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:55.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111884"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111867"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23947" version="7" class="patch">
      <metadata>
        <title>ELSA-2014:0311: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2014:0311-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0311.html" source="VENDOR"/>
        <reference ref_id="CVE-2006-7243" ref_url="http://linux.oracle.com/cve/CVE-2006-7243.html" source="CVE"/>
        <reference ref_id="CVE-2009-0689" ref_url="http://linux.oracle.com/cve/CVE-2009-0689.html" source="CVE"/>
        <description>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:46.706-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:06:52.659-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:09.946-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23947 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:26.102-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:05.311-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-devel is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112902"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113505"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113482"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113571"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113492"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113014"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113473"/>
          <criterion comment="php is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113469"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113459"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112611"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113489"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113372"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113235"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113456"/>
          <criterion comment="php-common is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113551"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112994"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113566"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:112913"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-44.el5_10" test_ref="oval:org.mitre.oval:tst:113144"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23946" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0821: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0821-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0821.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0801" ref_url="http://linux.oracle.com/cve/CVE-2013-0801.html" source="CVE"/>
        <reference ref_id="CVE-2013-1670" ref_url="http://linux.oracle.com/cve/CVE-2013-1670.html" source="CVE"/>
        <reference ref_id="CVE-2013-1674" ref_url="http://linux.oracle.com/cve/CVE-2013-1674.html" source="CVE"/>
        <reference ref_id="CVE-2013-1675" ref_url="http://linux.oracle.com/cve/CVE-2013-1675.html" source="CVE"/>
        <reference ref_id="CVE-2013-1676" ref_url="http://linux.oracle.com/cve/CVE-2013-1676.html" source="CVE"/>
        <reference ref_id="CVE-2013-1677" ref_url="http://linux.oracle.com/cve/CVE-2013-1677.html" source="CVE"/>
        <reference ref_id="CVE-2013-1678" ref_url="http://linux.oracle.com/cve/CVE-2013-1678.html" source="CVE"/>
        <reference ref_id="CVE-2013-1679" ref_url="http://linux.oracle.com/cve/CVE-2013-1679.html" source="CVE"/>
        <reference ref_id="CVE-2013-1680" ref_url="http://linux.oracle.com/cve/CVE-2013-1680.html" source="CVE"/>
        <reference ref_id="CVE-2013-1681" ref_url="http://linux.oracle.com/cve/CVE-2013-1681.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:35.323-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.700-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:52.233-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23946 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.778-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:55.106-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:111920"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:112002"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23945" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1288: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:1288-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1288.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3102" ref_url="http://linux.oracle.com/cve/CVE-2011-3102.html" source="CVE"/>
        <reference ref_id="CVE-2012-2807" ref_url="http://linux.oracle.com/cve/CVE-2012-2807.html" source="CVE"/>
        <description>Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:12.399-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.610-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:52.084-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23945 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:36.463-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:54.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:110961"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:111143"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:111093"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:110476"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:111154"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:111027"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:110924"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23942" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1102: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2012:1102-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1102.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1178" ref_url="http://linux.oracle.com/cve/CVE-2012-1178.html" source="CVE"/>
        <reference ref_id="CVE-2012-2318" ref_url="http://linux.oracle.com/cve/CVE-2012-2318.html" source="CVE"/>
        <reference ref_id="CVE-2012-3374" ref_url="http://linux.oracle.com/cve/CVE-2012-3374.html" source="CVE"/>
        <description>Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:44.067-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.376-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:51.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23942 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:35.689-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:54.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110373"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110676"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110752"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:109775"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110463"/>
            <criterion comment="finch is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110328"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110694"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110487"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110758"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110645"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110711"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110715"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110579"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110522"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110420"/>
            <criterion comment="finch is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110626"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110721"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110678"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23937" version="73" class="patch">
      <metadata>
        <title>ELSA-2012:1088: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1088-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1088.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1948" ref_url="http://linux.oracle.com/cve/CVE-2012-1948.html" source="CVE"/>
        <reference ref_id="CVE-2012-1950" ref_url="http://linux.oracle.com/cve/CVE-2012-1950.html" source="CVE"/>
        <reference ref_id="CVE-2012-1951" ref_url="http://linux.oracle.com/cve/CVE-2012-1951.html" source="CVE"/>
        <reference ref_id="CVE-2012-1952" ref_url="http://linux.oracle.com/cve/CVE-2012-1952.html" source="CVE"/>
        <reference ref_id="CVE-2012-1953" ref_url="http://linux.oracle.com/cve/CVE-2012-1953.html" source="CVE"/>
        <reference ref_id="CVE-2012-1954" ref_url="http://linux.oracle.com/cve/CVE-2012-1954.html" source="CVE"/>
        <reference ref_id="CVE-2012-1955" ref_url="http://linux.oracle.com/cve/CVE-2012-1955.html" source="CVE"/>
        <reference ref_id="CVE-2012-1957" ref_url="http://linux.oracle.com/cve/CVE-2012-1957.html" source="CVE"/>
        <reference ref_id="CVE-2012-1958" ref_url="http://linux.oracle.com/cve/CVE-2012-1958.html" source="CVE"/>
        <reference ref_id="CVE-2012-1959" ref_url="http://linux.oracle.com/cve/CVE-2012-1959.html" source="CVE"/>
        <reference ref_id="CVE-2012-1961" ref_url="http://linux.oracle.com/cve/CVE-2012-1961.html" source="CVE"/>
        <reference ref_id="CVE-2012-1962" ref_url="http://linux.oracle.com/cve/CVE-2012-1962.html" source="CVE"/>
        <reference ref_id="CVE-2012-1963" ref_url="http://linux.oracle.com/cve/CVE-2012-1963.html" source="CVE"/>
        <reference ref_id="CVE-2012-1964" ref_url="http://linux.oracle.com/cve/CVE-2012-1964.html" source="CVE"/>
        <reference ref_id="CVE-2012-1965" ref_url="http://linux.oracle.com/cve/CVE-2012-1965.html" source="CVE"/>
        <reference ref_id="CVE-2012-1966" ref_url="http://linux.oracle.com/cve/CVE-2012-1966.html" source="CVE"/>
        <reference ref_id="CVE-2012-1967" ref_url="http://linux.oracle.com/cve/CVE-2012-1967.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:50.245-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:29.789-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:50.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23937 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.998-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:53.639-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:110668"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:110357"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:110603"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110270"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110656"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23936" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:1590: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2012:1590-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1590.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3401" ref_url="http://linux.oracle.com/cve/CVE-2012-3401.html" source="CVE"/>
        <reference ref_id="CVE-2012-4447" ref_url="http://linux.oracle.com/cve/CVE-2012-4447.html" source="CVE"/>
        <reference ref_id="CVE-2012-4564" ref_url="http://linux.oracle.com/cve/CVE-2012-4564.html" source="CVE"/>
        <reference ref_id="CVE-2012-5581" ref_url="http://linux.oracle.com/cve/CVE-2012-5581.html" source="CVE"/>
        <description>Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:00.130-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:29.662-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:50.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23936 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.168-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:53.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:111247"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:111059"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:110879"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:110722"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:111208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23926" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1054: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2012:1054-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1054.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2088" ref_url="http://linux.oracle.com/cve/CVE-2012-2088.html" source="CVE"/>
        <reference ref_id="CVE-2012-2113" ref_url="http://linux.oracle.com/cve/CVE-2012-2113.html" source="CVE"/>
        <description>Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:47.393-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:28.200-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23926 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.560-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:110618"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:110740"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:110755"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:110512"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:110766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23922" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1512: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:1512-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1512.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5134" ref_url="http://linux.oracle.com/cve/CVE-2012-5134.html" source="CVE"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:05.640-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.810-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23922 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.066-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:111126"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:111008"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:111025"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:110997"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:111188"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:110336"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:111181"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23920" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0942: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2013:0942-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0942.html" source="VENDOR"/>
        <reference ref_id="CVE-2002-2443" ref_url="http://linux.oracle.com/cve/CVE-2002-2443.html" source="CVE"/>
        <description>schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:07.046-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.622-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23920 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.998-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:50.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:111862"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:111932"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112091"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112170"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112146"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:111885"/>
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112181"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112227"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112088"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:111893"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112087"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112176"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23916" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1812: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2013:1812-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1812.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:13.582-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.967-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:46.080-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23916 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.972-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:49.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:112384"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112239"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23912" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0588: gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2013:0588-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0588.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1619" ref_url="http://linux.oracle.com/cve/CVE-2013-1619.html" source="CVE"/>
        <description>The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:43.117-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.619-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:45.454-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23912 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.332-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:48.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111740"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111338"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111253"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111694"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:111054"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:111690"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:111761"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23909" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0587: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2013:0587-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0587.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4929" ref_url="http://linux.oracle.com/cve/CVE-2012-4929.html" source="CVE"/>
        <reference ref_id="CVE-2013-0166" ref_url="http://linux.oracle.com/cve/CVE-2013-0166.html" source="CVE"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <description>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:38.746-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.517-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:45.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23909 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.866-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:48.727-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111589"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111730"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111549"/>
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111490"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:111691"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:111455"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:111485"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23902" version="11" class="patch">
      <metadata>
        <title>ELSA-2014:0223: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2014:0223-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0223.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1960" ref_url="http://linux.oracle.com/cve/CVE-2013-1960.html" source="CVE"/>
        <reference ref_id="CVE-2013-1961" ref_url="http://linux.oracle.com/cve/CVE-2013-1961.html" source="CVE"/>
        <reference ref_id="CVE-2013-4231" ref_url="http://linux.oracle.com/cve/CVE-2013-4231.html" source="CVE"/>
        <reference ref_id="CVE-2013-4232" ref_url="http://linux.oracle.com/cve/CVE-2013-4232.html" source="CVE"/>
        <reference ref_id="CVE-2013-4243" ref_url="http://linux.oracle.com/cve/CVE-2013-4243.html" source="CVE"/>
        <reference ref_id="CVE-2013-4244" ref_url="http://linux.oracle.com/cve/CVE-2013-4244.html" source="CVE"/>
        <description>The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:41.078-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:06:43.175-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:09.432-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23902 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:22.561-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:04.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtiff is earlier than 0:3.8.2-19.el5_10" test_ref="oval:org.mitre.oval:tst:113531"/>
          <criterion comment="libtiff-devel is earlier than 0:3.8.2-19.el5_10" test_ref="oval:org.mitre.oval:tst:113298"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23894" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:1459: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference ref_id="ELSA-2013:1459-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1459.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6085" ref_url="http://linux.oracle.com/cve/CVE-2012-6085.html" source="CVE"/>
        <reference ref_id="CVE-2013-4351" ref_url="http://linux.oracle.com/cve/CVE-2013-4351.html" source="CVE"/>
        <reference ref_id="CVE-2013-4402" ref_url="http://linux.oracle.com/cve/CVE-2013-4402.html" source="CVE"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:06.641-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:24.151-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:41.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23894 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.379-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:45.909-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:112194"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:112175"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:112261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23892" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0185: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2014:0185-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0185.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6466" ref_url="http://linux.oracle.com/cve/CVE-2013-6466.html" source="CVE"/>
        <description>Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:40.367-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:23.216-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:40.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23892 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.167-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:45.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112563"/>
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112526"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112665"/>
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112613"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23881" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:1265: libxslt security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libxslt</product>
        </affected>
        <reference ref_id="ELSA-2012:1265-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-1265.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1202" ref_url="http://linux.oracle.com/cve/CVE-2011-1202.html" source="CVE"/>
        <reference ref_id="CVE-2011-3970" ref_url="http://linux.oracle.com/cve/CVE-2011-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-2825" ref_url="http://linux.oracle.com/cve/CVE-2012-2825.html" source="CVE"/>
        <reference ref_id="CVE-2012-2870" ref_url="http://linux.oracle.com/cve/CVE-2012-2870.html" source="CVE"/>
        <reference ref_id="CVE-2012-2871" ref_url="http://linux.oracle.com/cve/CVE-2012-2871.html" source="CVE"/>
        <reference ref_id="CVE-2012-2893" ref_url="http://linux.oracle.com/cve/CVE-2012-2893.html" source="CVE"/>
        <description>Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:42.935-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.813-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:36.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23881 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.273-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:42.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:111153"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:110754"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:111136"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxslt-devel is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:110842"/>
            <criterion comment="libxslt is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:111056"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:110771"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23879" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0737: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference ref_id="ELSA-2013:0737-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0737.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1845" ref_url="http://linux.oracle.com/cve/CVE-2013-1845.html" source="CVE"/>
        <reference ref_id="CVE-2013-1846" ref_url="http://linux.oracle.com/cve/CVE-2013-1846.html" source="CVE"/>
        <reference ref_id="CVE-2013-1847" ref_url="http://linux.oracle.com/cve/CVE-2013-1847.html" source="CVE"/>
        <reference ref_id="CVE-2013-1849" ref_url="http://linux.oracle.com/cve/CVE-2013-1849.html" source="CVE"/>
        <description>The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:55.077-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.614-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:36.289-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23879 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.788-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:41.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111641"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111527"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111340"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111912"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111566"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111487"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111891"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111856"/>
            <criterion comment="subversion is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111653"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111952"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111774"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111962"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111873"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111669"/>
            <criterion comment="subversion is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111344"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23874" version="53" class="patch">
      <metadata>
        <title>ELSA-2013:0144: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0144-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0144.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0744" ref_url="http://linux.oracle.com/cve/CVE-2013-0744.html" source="CVE"/>
        <reference ref_id="CVE-2013-0746" ref_url="http://linux.oracle.com/cve/CVE-2013-0746.html" source="CVE"/>
        <reference ref_id="CVE-2013-0748" ref_url="http://linux.oracle.com/cve/CVE-2013-0748.html" source="CVE"/>
        <reference ref_id="CVE-2013-0750" ref_url="http://linux.oracle.com/cve/CVE-2013-0750.html" source="CVE"/>
        <reference ref_id="CVE-2013-0753" ref_url="http://linux.oracle.com/cve/CVE-2013-0753.html" source="CVE"/>
        <reference ref_id="CVE-2013-0754" ref_url="http://linux.oracle.com/cve/CVE-2013-0754.html" source="CVE"/>
        <reference ref_id="CVE-2013-0758" ref_url="http://linux.oracle.com/cve/CVE-2013-0758.html" source="CVE"/>
        <reference ref_id="CVE-2013-0759" ref_url="http://linux.oracle.com/cve/CVE-2013-0759.html" source="CVE"/>
        <reference ref_id="CVE-2013-0762" ref_url="http://linux.oracle.com/cve/CVE-2013-0762.html" source="CVE"/>
        <reference ref_id="CVE-2013-0766" ref_url="http://linux.oracle.com/cve/CVE-2013-0766.html" source="CVE"/>
        <reference ref_id="CVE-2013-0767" ref_url="http://linux.oracle.com/cve/CVE-2013-0767.html" source="CVE"/>
        <reference ref_id="CVE-2013-0769" ref_url="http://linux.oracle.com/cve/CVE-2013-0769.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:30.810-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.760-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:34.568-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23874 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.513-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:40.795-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:111305"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:110866"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:110941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:110956"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:111356"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:110858"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23867" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0788: subscription-manager security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subscription-manager</product>
        </affected>
        <reference ref_id="ELSA-2013:0788-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0788.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6137" ref_url="http://linux.oracle.com/cve/CVE-2012-6137.html" source="CVE"/>
        <description>rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:50.890-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.146-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:33.501-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23867 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.254-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:39.823-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:112034"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:111926"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:111981"/>
            <criterion comment="subscription-manager is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:111863"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:111850"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:112027"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:111954"/>
            <criterion comment="subscription-manager is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:112054"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23863" version="12" class="patch">
      <metadata>
        <title>ELSA-2014:0285: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2014:0285-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0285.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2929" ref_url="http://linux.oracle.com/cve/CVE-2013-2929.html" source="CVE"/>
        <reference ref_id="CVE-2013-4483" ref_url="http://linux.oracle.com/cve/CVE-2013-4483.html" source="CVE"/>
        <reference ref_id="CVE-2013-4554" ref_url="http://linux.oracle.com/cve/CVE-2013-4554.html" source="CVE"/>
        <reference ref_id="CVE-2013-6381" ref_url="http://linux.oracle.com/cve/CVE-2013-6381.html" source="CVE"/>
        <reference ref_id="CVE-2013-6383" ref_url="http://linux.oracle.com/cve/CVE-2013-6383.html" source="CVE"/>
        <reference ref_id="CVE-2013-6885" ref_url="http://linux.oracle.com/cve/CVE-2013-6885.html" source="CVE"/>
        <reference ref_id="CVE-2013-7263" ref_url="http://linux.oracle.com/cve/CVE-2013-7263.html" source="CVE"/>
        <description>The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:48.643-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:06:32.133-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:09.032-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23863 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:21.460-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:02.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113540"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113502"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113486"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113395"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113536"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113424"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113149"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113521"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113377"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113565"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:113483"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.6.1.el5" test_ref="oval:org.mitre.oval:tst:112780"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23862" version="97" class="patch">
      <metadata>
        <title>ELSA-2012:1211: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1211-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1211.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1970" ref_url="http://linux.oracle.com/cve/CVE-2012-1970.html" source="CVE"/>
        <reference ref_id="CVE-2012-1972" ref_url="http://linux.oracle.com/cve/CVE-2012-1972.html" source="CVE"/>
        <reference ref_id="CVE-2012-1973" ref_url="http://linux.oracle.com/cve/CVE-2012-1973.html" source="CVE"/>
        <reference ref_id="CVE-2012-1974" ref_url="http://linux.oracle.com/cve/CVE-2012-1974.html" source="CVE"/>
        <reference ref_id="CVE-2012-1975" ref_url="http://linux.oracle.com/cve/CVE-2012-1975.html" source="CVE"/>
        <reference ref_id="CVE-2012-1976" ref_url="http://linux.oracle.com/cve/CVE-2012-1976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3956" ref_url="http://linux.oracle.com/cve/CVE-2012-3956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3957" ref_url="http://linux.oracle.com/cve/CVE-2012-3957.html" source="CVE"/>
        <reference ref_id="CVE-2012-3958" ref_url="http://linux.oracle.com/cve/CVE-2012-3958.html" source="CVE"/>
        <reference ref_id="CVE-2012-3959" ref_url="http://linux.oracle.com/cve/CVE-2012-3959.html" source="CVE"/>
        <reference ref_id="CVE-2012-3960" ref_url="http://linux.oracle.com/cve/CVE-2012-3960.html" source="CVE"/>
        <reference ref_id="CVE-2012-3961" ref_url="http://linux.oracle.com/cve/CVE-2012-3961.html" source="CVE"/>
        <reference ref_id="CVE-2012-3962" ref_url="http://linux.oracle.com/cve/CVE-2012-3962.html" source="CVE"/>
        <reference ref_id="CVE-2012-3963" ref_url="http://linux.oracle.com/cve/CVE-2012-3963.html" source="CVE"/>
        <reference ref_id="CVE-2012-3964" ref_url="http://linux.oracle.com/cve/CVE-2012-3964.html" source="CVE"/>
        <reference ref_id="CVE-2012-3966" ref_url="http://linux.oracle.com/cve/CVE-2012-3966.html" source="CVE"/>
        <reference ref_id="CVE-2012-3967" ref_url="http://linux.oracle.com/cve/CVE-2012-3967.html" source="CVE"/>
        <reference ref_id="CVE-2012-3968" ref_url="http://linux.oracle.com/cve/CVE-2012-3968.html" source="CVE"/>
        <reference ref_id="CVE-2012-3969" ref_url="http://linux.oracle.com/cve/CVE-2012-3969.html" source="CVE"/>
        <reference ref_id="CVE-2012-3970" ref_url="http://linux.oracle.com/cve/CVE-2012-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-3972" ref_url="http://linux.oracle.com/cve/CVE-2012-3972.html" source="CVE"/>
        <reference ref_id="CVE-2012-3978" ref_url="http://linux.oracle.com/cve/CVE-2012-3978.html" source="CVE"/>
        <reference ref_id="CVE-2012-3980" ref_url="http://linux.oracle.com/cve/CVE-2012-3980.html" source="CVE"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:34.186-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:18.141-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:31.301-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23862 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.358-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:38.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:110681"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110922"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23860" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1081: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2012:1081-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1081.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2337" ref_url="http://linux.oracle.com/cve/CVE-2012-2337.html" source="CVE"/>
        <description>sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:40.847-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.995-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:31.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23860 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.144-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:38.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8" test_ref="oval:org.mitre.oval:tst:110692"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="sudo is earlier than 0:1.7.4p5-12.el6_3" test_ref="oval:org.mitre.oval:tst:110408"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23855" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1806: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2013:1806-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1806.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4408" ref_url="http://linux.oracle.com/cve/CVE-2013-4408.html" source="CVE"/>
        <reference ref_id="CVE-2013-4475" ref_url="http://linux.oracle.com/cve/CVE-2013-4475.html" source="CVE"/>
        <description>Samba 3.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:17.238-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.362-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:30.332-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23855 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.431-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:37.740-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112434"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112578"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112650"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:111735"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112487"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112371"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112191"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112468"/>
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112630"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112573"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112418"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112117"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:111713"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112394"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112707"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112706"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112647"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112662"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112546"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23847" version="53" class="patch">
      <metadata>
        <title>ELSA-2013:0145: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0145-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0145.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0744" ref_url="http://linux.oracle.com/cve/CVE-2013-0744.html" source="CVE"/>
        <reference ref_id="CVE-2013-0746" ref_url="http://linux.oracle.com/cve/CVE-2013-0746.html" source="CVE"/>
        <reference ref_id="CVE-2013-0748" ref_url="http://linux.oracle.com/cve/CVE-2013-0748.html" source="CVE"/>
        <reference ref_id="CVE-2013-0750" ref_url="http://linux.oracle.com/cve/CVE-2013-0750.html" source="CVE"/>
        <reference ref_id="CVE-2013-0753" ref_url="http://linux.oracle.com/cve/CVE-2013-0753.html" source="CVE"/>
        <reference ref_id="CVE-2013-0754" ref_url="http://linux.oracle.com/cve/CVE-2013-0754.html" source="CVE"/>
        <reference ref_id="CVE-2013-0758" ref_url="http://linux.oracle.com/cve/CVE-2013-0758.html" source="CVE"/>
        <reference ref_id="CVE-2013-0759" ref_url="http://linux.oracle.com/cve/CVE-2013-0759.html" source="CVE"/>
        <reference ref_id="CVE-2013-0762" ref_url="http://linux.oracle.com/cve/CVE-2013-0762.html" source="CVE"/>
        <reference ref_id="CVE-2013-0766" ref_url="http://linux.oracle.com/cve/CVE-2013-0766.html" source="CVE"/>
        <reference ref_id="CVE-2013-0767" ref_url="http://linux.oracle.com/cve/CVE-2013-0767.html" source="CVE"/>
        <reference ref_id="CVE-2013-0769" ref_url="http://linux.oracle.com/cve/CVE-2013-0769.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:20.443-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:15.836-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:28.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23847 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.058-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:36.467-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el6_3" test_ref="oval:org.mitre.oval:tst:111316"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el5_9" test_ref="oval:org.mitre.oval:tst:111201"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23841" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1037: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1037-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1037.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2143" ref_url="http://linux.oracle.com/cve/CVE-2012-2143.html" source="CVE"/>
        <reference ref_id="CVE-2012-2655" ref_url="http://linux.oracle.com/cve/CVE-2012-2655.html" source="CVE"/>
        <description>PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:38.652-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:15.090-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:27.352-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23841 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.914-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:35.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110568"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110629"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110509"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110621"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110616"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110303"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110468"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110630"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110507"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110560"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110617"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110387"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110545"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110554"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110623"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110201"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110486"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110581"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110372"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:109699"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:109991"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110634"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23838" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:1778: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2013:1778-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1778.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5576" ref_url="http://linux.oracle.com/cve/CVE-2012-5576.html" source="CVE"/>
        <reference ref_id="CVE-2013-1913" ref_url="http://linux.oracle.com/cve/CVE-2013-1913.html" source="CVE"/>
        <reference ref_id="CVE-2013-1978" ref_url="http://linux.oracle.com/cve/CVE-2013-1978.html" source="CVE"/>
        <description>Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:16.585-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:14.521-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:26.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23838 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.661-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:35.244-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:111598"/>
            <criterion comment="gimp-devel is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:112330"/>
            <criterion comment="gimp is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:112531"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112435"/>
            <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112451"/>
            <criterion comment="gimp-devel is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112413"/>
            <criterion comment="gimp is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:111649"/>
            <criterion comment="gimp-help-browser is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112498"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23826" version="45" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0715: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0715-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0715.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3101" ref_url="http://linux.oracle.com/cve/CVE-2011-3101.html" source="CVE"/>
        <reference ref_id="CVE-2012-1937" ref_url="http://linux.oracle.com/cve/CVE-2012-1937.html" source="CVE"/>
        <reference ref_id="CVE-2012-1938" ref_url="http://linux.oracle.com/cve/CVE-2012-1938.html" source="CVE"/>
        <reference ref_id="CVE-2012-1939" ref_url="http://linux.oracle.com/cve/CVE-2012-1939.html" source="CVE"/>
        <reference ref_id="CVE-2012-1940" ref_url="http://linux.oracle.com/cve/CVE-2012-1940.html" source="CVE"/>
        <reference ref_id="CVE-2012-1941" ref_url="http://linux.oracle.com/cve/CVE-2012-1941.html" source="CVE"/>
        <reference ref_id="CVE-2012-1944" ref_url="http://linux.oracle.com/cve/CVE-2012-1944.html" source="CVE"/>
        <reference ref_id="CVE-2012-1945" ref_url="http://linux.oracle.com/cve/CVE-2012-1945.html" source="CVE"/>
        <reference ref_id="CVE-2012-1946" ref_url="http://linux.oracle.com/cve/CVE-2012-1946.html" source="CVE"/>
        <reference ref_id="CVE-2012-1947" ref_url="http://linux.oracle.com/cve/CVE-2012-1947.html" source="CVE"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:29.383-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:12.940-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:24.891-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23826 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:34.479-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:56:32.614-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:56:32.614-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el5_8" test_ref="oval:org.mitre.oval:tst:110394"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el6_2" test_ref="oval:org.mitre.oval:tst:110019"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23822" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0981: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0981-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0981.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1682" ref_url="http://linux.oracle.com/cve/CVE-2013-1682.html" source="CVE"/>
        <reference ref_id="CVE-2013-1684" ref_url="http://linux.oracle.com/cve/CVE-2013-1684.html" source="CVE"/>
        <reference ref_id="CVE-2013-1685" ref_url="http://linux.oracle.com/cve/CVE-2013-1685.html" source="CVE"/>
        <reference ref_id="CVE-2013-1686" ref_url="http://linux.oracle.com/cve/CVE-2013-1686.html" source="CVE"/>
        <reference ref_id="CVE-2013-1687" ref_url="http://linux.oracle.com/cve/CVE-2013-1687.html" source="CVE"/>
        <reference ref_id="CVE-2013-1690" ref_url="http://linux.oracle.com/cve/CVE-2013-1690.html" source="CVE"/>
        <reference ref_id="CVE-2013-1692" ref_url="http://linux.oracle.com/cve/CVE-2013-1692.html" source="CVE"/>
        <reference ref_id="CVE-2013-1693" ref_url="http://linux.oracle.com/cve/CVE-2013-1693.html" source="CVE"/>
        <reference ref_id="CVE-2013-1694" ref_url="http://linux.oracle.com/cve/CVE-2013-1694.html" source="CVE"/>
        <reference ref_id="CVE-2013-1697" ref_url="http://linux.oracle.com/cve/CVE-2013-1697.html" source="CVE"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:09.982-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:11.680-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:23.916-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23822 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:47.988-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:112067"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:111978"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:111703"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:112213"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:112107"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:111905"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23820" version="69" class="patch">
      <metadata>
        <title>ELSA-2012:1482: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1482-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1482.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4201" ref_url="http://linux.oracle.com/cve/CVE-2012-4201.html" source="CVE"/>
        <reference ref_id="CVE-2012-4202" ref_url="http://linux.oracle.com/cve/CVE-2012-4202.html" source="CVE"/>
        <reference ref_id="CVE-2012-4207" ref_url="http://linux.oracle.com/cve/CVE-2012-4207.html" source="CVE"/>
        <reference ref_id="CVE-2012-4209" ref_url="http://linux.oracle.com/cve/CVE-2012-4209.html" source="CVE"/>
        <reference ref_id="CVE-2012-4210" ref_url="http://linux.oracle.com/cve/CVE-2012-4210.html" source="CVE"/>
        <reference ref_id="CVE-2012-4214" ref_url="http://linux.oracle.com/cve/CVE-2012-4214.html" source="CVE"/>
        <reference ref_id="CVE-2012-4215" ref_url="http://linux.oracle.com/cve/CVE-2012-4215.html" source="CVE"/>
        <reference ref_id="CVE-2012-4216" ref_url="http://linux.oracle.com/cve/CVE-2012-4216.html" source="CVE"/>
        <reference ref_id="CVE-2012-5829" ref_url="http://linux.oracle.com/cve/CVE-2012-5829.html" source="CVE"/>
        <reference ref_id="CVE-2012-5830" ref_url="http://linux.oracle.com/cve/CVE-2012-5830.html" source="CVE"/>
        <reference ref_id="CVE-2012-5833" ref_url="http://linux.oracle.com/cve/CVE-2012-5833.html" source="CVE"/>
        <reference ref_id="CVE-2012-5835" ref_url="http://linux.oracle.com/cve/CVE-2012-5835.html" source="CVE"/>
        <reference ref_id="CVE-2012-5839" ref_url="http://linux.oracle.com/cve/CVE-2012-5839.html" source="CVE"/>
        <reference ref_id="CVE-2012-5840" ref_url="http://linux.oracle.com/cve/CVE-2012-5840.html" source="CVE"/>
        <reference ref_id="CVE-2012-5841" ref_url="http://linux.oracle.com/cve/CVE-2012-5841.html" source="CVE"/>
        <reference ref_id="CVE-2012-5842" ref_url="http://linux.oracle.com/cve/CVE-2012-5842.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:39:59.673-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.992-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:23.086-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23820 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.681-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110649"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110953"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:111108"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:111195"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:111217"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:111183"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23818" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0216: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2013:0216-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0216.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5669" ref_url="http://linux.oracle.com/cve/CVE-2012-5669.html" source="CVE"/>
        <description>The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:23.342-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.746-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23818 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.318-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:111325"/>
            <criterion comment="freetype is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:111169"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:111219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:110710"/>
            <criterion comment="freetype is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:111390"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:111361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23816" version="5" class="patch">
      <metadata>
        <title>ELSA-2013:1861: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1861-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1861.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:01.321-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.678-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23816 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.780-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112771"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112600"/>
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112710"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112558"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112464"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112182"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112735"/>
            <criterion comment="nss is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112375"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112538"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23814" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0376: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2012:0376-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0376.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0875" ref_url="http://linux.oracle.com/cve/CVE-2012-0875.html" source="CVE"/>
        <description>SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data, which triggers a read of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:10.075-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.495-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23814 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.848-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:32.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:110063"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109900"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109877"/>
            <criterion comment="systemtap is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109867"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109850"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109794"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109915"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:110108"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109921"/>
            <criterion comment="systemtap is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109781"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109976"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:110121"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109818"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23802" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0568: dbus-glib security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus-glib</product>
        </affected>
        <reference ref_id="ELSA-2013:0568-03" ref_url="http://linux.oracle.com/errata/ELSA-2013-0568.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0292" ref_url="http://linux.oracle.com/cve/CVE-2013-0292.html" source="CVE"/>
        <description>The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:33.679-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.174-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:18.022-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23802 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.509-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:111559"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:111724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:111522"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:111676"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23801" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1156: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:1156-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1156.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1896" ref_url="http://linux.oracle.com/cve/CVE-2013-1896.html" source="CVE"/>
        <description>mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:05.309-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.074-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:17.888-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23801 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.523-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.835-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="mod_ssl is earlier than 1:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112368"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:111602"/>
            <criterion comment="httpd is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112058"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112390"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112223"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112020"/>
            <criterion comment="httpd is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112217"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112103"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112346"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23798" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0546: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0546-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0546.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1823" ref_url="http://linux.oracle.com/cve/CVE-2012-1823.html" source="CVE"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:20.231-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.739-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:17.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23798 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:47.372-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110119"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110178"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109644"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109653"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110090"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110145"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109700"/>
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109218"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109724"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109744"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109904"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110172"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109360"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110218"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109963"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109973"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109843"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110078"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110023"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110059"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110061"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109861"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109860"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110164"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109918"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110166"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109542"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110085"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109225"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109679"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109888"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109908"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109925"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109993"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110130"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110009"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109959"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109558"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109805"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109545"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109851"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110105"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109740"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109760"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109607"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23793" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0710: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0710-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0710.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3101" ref_url="http://linux.oracle.com/cve/CVE-2011-3101.html" source="CVE"/>
        <reference ref_id="CVE-2012-1937" ref_url="http://linux.oracle.com/cve/CVE-2012-1937.html" source="CVE"/>
        <reference ref_id="CVE-2012-1938" ref_url="http://linux.oracle.com/cve/CVE-2012-1938.html" source="CVE"/>
        <reference ref_id="CVE-2012-1939" ref_url="http://linux.oracle.com/cve/CVE-2012-1939.html" source="CVE"/>
        <reference ref_id="CVE-2012-1940" ref_url="http://linux.oracle.com/cve/CVE-2012-1940.html" source="CVE"/>
        <reference ref_id="CVE-2012-1941" ref_url="http://linux.oracle.com/cve/CVE-2012-1941.html" source="CVE"/>
        <reference ref_id="CVE-2012-1944" ref_url="http://linux.oracle.com/cve/CVE-2012-1944.html" source="CVE"/>
        <reference ref_id="CVE-2012-1945" ref_url="http://linux.oracle.com/cve/CVE-2012-1945.html" source="CVE"/>
        <reference ref_id="CVE-2012-1946" ref_url="http://linux.oracle.com/cve/CVE-2012-1946.html" source="CVE"/>
        <reference ref_id="CVE-2012-1947" ref_url="http://linux.oracle.com/cve/CVE-2012-1947.html" source="CVE"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:40.703-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.872-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:16.030-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23793 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.683-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:28.368-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:110020"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:110382"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:110254"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:109813"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:110485"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:110443"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23786" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0143: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0143-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0143.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3026" ref_url="http://linux.oracle.com/cve/CVE-2011-3026.html" source="CVE"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:05.100-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.238-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:15.229-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23786 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.225-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:27.858-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:109339"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:109736"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:109919"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:110032"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23783" version="53" class="patch">
      <metadata>
        <title>ELSA-2012:0515: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0515-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0515.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3062" ref_url="http://linux.oracle.com/cve/CVE-2011-3062.html" source="CVE"/>
        <reference ref_id="CVE-2012-0467" ref_url="http://linux.oracle.com/cve/CVE-2012-0467.html" source="CVE"/>
        <reference ref_id="CVE-2012-0468" ref_url="http://linux.oracle.com/cve/CVE-2012-0468.html" source="CVE"/>
        <reference ref_id="CVE-2012-0469" ref_url="http://linux.oracle.com/cve/CVE-2012-0469.html" source="CVE"/>
        <reference ref_id="CVE-2012-0470" ref_url="http://linux.oracle.com/cve/CVE-2012-0470.html" source="CVE"/>
        <reference ref_id="CVE-2012-0471" ref_url="http://linux.oracle.com/cve/CVE-2012-0471.html" source="CVE"/>
        <reference ref_id="CVE-2012-0472" ref_url="http://linux.oracle.com/cve/CVE-2012-0472.html" source="CVE"/>
        <reference ref_id="CVE-2012-0473" ref_url="http://linux.oracle.com/cve/CVE-2012-0473.html" source="CVE"/>
        <reference ref_id="CVE-2012-0474" ref_url="http://linux.oracle.com/cve/CVE-2012-0474.html" source="CVE"/>
        <reference ref_id="CVE-2012-0477" ref_url="http://linux.oracle.com/cve/CVE-2012-0477.html" source="CVE"/>
        <reference ref_id="CVE-2012-0478" ref_url="http://linux.oracle.com/cve/CVE-2012-0478.html" source="CVE"/>
        <reference ref_id="CVE-2012-0479" ref_url="http://linux.oracle.com/cve/CVE-2012-0479.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:18.680-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:03.965-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:13.265-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23783 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:56.652-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:26.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:109693"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:110186"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:110006"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:109623"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:110095"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:110183"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23781" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0412: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0412-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0412.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:37.600-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:17.393-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:54.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23781 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:32.031-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:56:00.595-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:56:00.595-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113278"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114098"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113617"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113573"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113805"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113763"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114219"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114226"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113404"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114209"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113971"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23770" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0678: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:0678-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0678.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0866" ref_url="http://linux.oracle.com/cve/CVE-2012-0866.html" source="CVE"/>
        <reference ref_id="CVE-2012-0867" ref_url="http://linux.oracle.com/cve/CVE-2012-0867.html" source="CVE"/>
        <reference ref_id="CVE-2012-0868" ref_url="http://linux.oracle.com/cve/CVE-2012-0868.html" source="CVE"/>
        <description>CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:33.822-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:01.634-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:09.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23770 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.328-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:24.170-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109738"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109949"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110133"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110096"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109667"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110229"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109290"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109270"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110333"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110177"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110159"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109342"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:109657"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110341"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110267"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110246"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110160"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110249"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:109942"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:109561"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110230"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110281"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23768" version="61" class="patch">
      <metadata>
        <title>ELSA-2012:0467: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2012:0467-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0467.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1126" ref_url="http://linux.oracle.com/cve/CVE-2012-1126.html" source="CVE"/>
        <reference ref_id="CVE-2012-1127" ref_url="http://linux.oracle.com/cve/CVE-2012-1127.html" source="CVE"/>
        <reference ref_id="CVE-2012-1130" ref_url="http://linux.oracle.com/cve/CVE-2012-1130.html" source="CVE"/>
        <reference ref_id="CVE-2012-1131" ref_url="http://linux.oracle.com/cve/CVE-2012-1131.html" source="CVE"/>
        <reference ref_id="CVE-2012-1132" ref_url="http://linux.oracle.com/cve/CVE-2012-1132.html" source="CVE"/>
        <reference ref_id="CVE-2012-1134" ref_url="http://linux.oracle.com/cve/CVE-2012-1134.html" source="CVE"/>
        <reference ref_id="CVE-2012-1136" ref_url="http://linux.oracle.com/cve/CVE-2012-1136.html" source="CVE"/>
        <reference ref_id="CVE-2012-1137" ref_url="http://linux.oracle.com/cve/CVE-2012-1137.html" source="CVE"/>
        <reference ref_id="CVE-2012-1139" ref_url="http://linux.oracle.com/cve/CVE-2012-1139.html" source="CVE"/>
        <reference ref_id="CVE-2012-1140" ref_url="http://linux.oracle.com/cve/CVE-2012-1140.html" source="CVE"/>
        <reference ref_id="CVE-2012-1141" ref_url="http://linux.oracle.com/cve/CVE-2012-1141.html" source="CVE"/>
        <reference ref_id="CVE-2012-1142" ref_url="http://linux.oracle.com/cve/CVE-2012-1142.html" source="CVE"/>
        <reference ref_id="CVE-2012-1143" ref_url="http://linux.oracle.com/cve/CVE-2012-1143.html" source="CVE"/>
        <reference ref_id="CVE-2012-1144" ref_url="http://linux.oracle.com/cve/CVE-2012-1144.html" source="CVE"/>
        <description>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:07.365-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:01.226-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:08.756-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23768 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.997-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:109745"/>
            <criterion comment="freetype is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:110076"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:109509"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:110132"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:109997"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:109716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23767" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1269: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1269-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1269.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1718" ref_url="http://linux.oracle.com/cve/CVE-2013-1718.html" source="CVE"/>
        <reference ref_id="CVE-2013-1722" ref_url="http://linux.oracle.com/cve/CVE-2013-1722.html" source="CVE"/>
        <reference ref_id="CVE-2013-1725" ref_url="http://linux.oracle.com/cve/CVE-2013-1725.html" source="CVE"/>
        <reference ref_id="CVE-2013-1730" ref_url="http://linux.oracle.com/cve/CVE-2013-1730.html" source="CVE"/>
        <reference ref_id="CVE-2013-1732" ref_url="http://linux.oracle.com/cve/CVE-2013-1732.html" source="CVE"/>
        <reference ref_id="CVE-2013-1735" ref_url="http://linux.oracle.com/cve/CVE-2013-1735.html" source="CVE"/>
        <reference ref_id="CVE-2013-1736" ref_url="http://linux.oracle.com/cve/CVE-2013-1736.html" source="CVE"/>
        <reference ref_id="CVE-2013-1737" ref_url="http://linux.oracle.com/cve/CVE-2013-1737.html" source="CVE"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:01.815-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:01.021-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:08.396-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23767 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:47.694-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112433"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:111848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23766" version="29" class="patch">
      <metadata>
        <title>ELSA-2014:0132: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0132-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0132.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:38.893-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.821-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:08.119-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23766 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:52.657-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:111899"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:112883"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23764" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0827: openswan security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2013:0827-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0827.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2053" ref_url="http://linux.oracle.com/cve/CVE-2013-2053.html" source="CVE"/>
        <description>Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.	 NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:34.609-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.595-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.841-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23764 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:51.358-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:111989"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:111580"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:111657"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:111709"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23763" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1359: xorg-x11-server security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2011:1359-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1359.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4818" ref_url="http://linux.oracle.com/cve/CVE-2010-4818.html" source="CVE"/>
        <reference ref_id="CVE-2010-4819" ref_url="http://linux.oracle.com/cve/CVE-2010-4819.html" source="CVE"/>
        <description>The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:03.828-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.484-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.665-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23763 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:52.859-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109266"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109352"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:108472"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109348"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109436"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109067"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109197"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109190"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109134"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109433"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109458"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109414"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109025"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109406"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109269"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109208"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109141"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23762" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0136: libvorbis security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 4</platform>
          <product>libvorbis</product>
        </affected>
        <reference ref_id="ELSA-2012:0136-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0136.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0444" ref_url="http://linux.oracle.com/cve/CVE-2012-0444.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:06.249-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.404-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23762 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.584-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:55:25.644-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:55:25.644-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libvorbis is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109389"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:110000"/>
            <criterion comment="libvorbis-devel-docs is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109624"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:109622"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:109883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23758" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0451: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference ref_id="ELSA-2012:0451-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0451.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0060" ref_url="http://linux.oracle.com/cve/CVE-2012-0060.html" source="CVE"/>
        <reference ref_id="CVE-2012-0061" ref_url="http://linux.oracle.com/cve/CVE-2012-0061.html" source="CVE"/>
        <reference ref_id="CVE-2012-0815" ref_url="http://linux.oracle.com/cve/CVE-2012-0815.html" source="CVE"/>
        <description>The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:16.884-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:59.939-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:06.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23758 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.099-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:22.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109636"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109834"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:110162"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109442"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:110109"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109246"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109789"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109954"/>
            <criterion comment="rpm is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109725"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109798"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:110060"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109497"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:110101"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109579"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23757" version="61" class="patch">
      <metadata>
        <title>ELSA-2012:1089: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1089-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1089.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1948" ref_url="http://linux.oracle.com/cve/CVE-2012-1948.html" source="CVE"/>
        <reference ref_id="CVE-2012-1951" ref_url="http://linux.oracle.com/cve/CVE-2012-1951.html" source="CVE"/>
        <reference ref_id="CVE-2012-1952" ref_url="http://linux.oracle.com/cve/CVE-2012-1952.html" source="CVE"/>
        <reference ref_id="CVE-2012-1953" ref_url="http://linux.oracle.com/cve/CVE-2012-1953.html" source="CVE"/>
        <reference ref_id="CVE-2012-1954" ref_url="http://linux.oracle.com/cve/CVE-2012-1954.html" source="CVE"/>
        <reference ref_id="CVE-2012-1955" ref_url="http://linux.oracle.com/cve/CVE-2012-1955.html" source="CVE"/>
        <reference ref_id="CVE-2012-1957" ref_url="http://linux.oracle.com/cve/CVE-2012-1957.html" source="CVE"/>
        <reference ref_id="CVE-2012-1958" ref_url="http://linux.oracle.com/cve/CVE-2012-1958.html" source="CVE"/>
        <reference ref_id="CVE-2012-1959" ref_url="http://linux.oracle.com/cve/CVE-2012-1959.html" source="CVE"/>
        <reference ref_id="CVE-2012-1961" ref_url="http://linux.oracle.com/cve/CVE-2012-1961.html" source="CVE"/>
        <reference ref_id="CVE-2012-1962" ref_url="http://linux.oracle.com/cve/CVE-2012-1962.html" source="CVE"/>
        <reference ref_id="CVE-2012-1963" ref_url="http://linux.oracle.com/cve/CVE-2012-1963.html" source="CVE"/>
        <reference ref_id="CVE-2012-1964" ref_url="http://linux.oracle.com/cve/CVE-2012-1964.html" source="CVE"/>
        <reference ref_id="CVE-2012-1967" ref_url="http://linux.oracle.com/cve/CVE-2012-1967.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:51.106-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:59.558-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:06.325-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23757 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.142-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:22.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:110283"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110589"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23755" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0275: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0275-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0275.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-1484" ref_url="http://linux.oracle.com/cve/CVE-2013-1484.html" source="CVE"/>
        <reference ref_id="CVE-2013-1485" ref_url="http://linux.oracle.com/cve/CVE-2013-1485.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:27.016-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.501-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23755 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.011-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:21.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111067"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:110817"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111459"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111122"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111375"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111512"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111420"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111381"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111439"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111358"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23754" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1282: nss and nspr security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nspr</product>
        </affected>
        <reference ref_id="ELSA-2011:1282-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1282.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities.
It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update renders any HTTPS certificates signed by that CA
as untrusted. This covers all uses of the certificates, including SSL,
S/MIME, and code signing. (BZ#734316)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
These updated packages upgrade NSS to version 3.12.10 on Red Hat Enterprise
Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Red Hat
Enterprise Linux 4 and 5, as required by the NSS update. The packages for
Red Hat Enterprise Linux 6 include a backported patch.
All NSS and NSPR users should upgrade to these updated packages, which
correct this issue. After installing the update, applications using NSS and
NSPR must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:18.457-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.429-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.378-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23754 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.259-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:21.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nspr is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:109162"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:109355"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109276"/>
            <criterion comment="nss-tools is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109356"/>
            <criterion comment="nss is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109368"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:109205"/>
            <criterion comment="nss-tools is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:108706"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:109051"/>
            <criterion comment="nss is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:109179"/>
            <criterion comment="nss-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:108866"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23752" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1116: perl-DBD-Pg security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference ref_id="ELSA-2012:1116-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1116.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1151" ref_url="http://linux.oracle.com/cve/CVE-2012-1151.html" source="CVE"/>
        <description>Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:54.746-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.224-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.032-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23752 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.739-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="perl-DBD-Pg is earlier than 0:1.49-4.el5_8" test_ref="oval:org.mitre.oval:tst:110730"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="perl-DBD-Pg is earlier than 0:2.15.1-4.el6_3" test_ref="oval:org.mitre.oval:tst:110301"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23751" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0407: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference ref_id="ELSA-2012:0407-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0407.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3045" ref_url="http://linux.oracle.com/cve/CVE-2011-3045.html" source="CVE"/>
        <description>Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:04.095-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.147-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:03.920-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23751 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:58.823-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:110080"/>
            <criterion comment="libpng is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:110139"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-static is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:109628"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:109857"/>
            <criterion comment="libpng is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:109916"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23750" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1317: cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference ref_id="ELSA-2011:1317-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1317.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3208" ref_url="http://linux.oracle.com/cve/CVE-2011-3208.html" source="CVE"/>
        <description>Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:52.858-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.060-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:03.783-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23750 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.639-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:109024"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:109379"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:108988"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:109144"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109074"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109258"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109125"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23746" version="53" class="patch">
      <metadata>
        <title>ELSA-2011:1380: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2011:1380-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1380.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3389" ref_url="http://linux.oracle.com/cve/CVE-2011-3389.html" source="CVE"/>
        <reference ref_id="CVE-2011-3521" ref_url="http://linux.oracle.com/cve/CVE-2011-3521.html" source="CVE"/>
        <reference ref_id="CVE-2011-3544" ref_url="http://linux.oracle.com/cve/CVE-2011-3544.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3551" ref_url="http://linux.oracle.com/cve/CVE-2011-3551.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3553" ref_url="http://linux.oracle.com/cve/CVE-2011-3553.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <reference ref_id="CVE-2011-3557" ref_url="http://linux.oracle.com/cve/CVE-2011-3557.html" source="CVE"/>
        <reference ref_id="CVE-2011-3558" ref_url="http://linux.oracle.com/cve/CVE-2011-3558.html" source="CVE"/>
        <reference ref_id="CVE-2011-3560" ref_url="http://linux.oracle.com/cve/CVE-2011-3560.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:01.220-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:56.806-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:01.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23746 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:58.666-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:19.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109037"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109386"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109431"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109087"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109303"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:108661"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:109461"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:108875"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:109159"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:109449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23739" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1815: icu security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>icu</product>
        </affected>
        <reference ref_id="ELSA-2011:1815-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1815.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4599" ref_url="http://linux.oracle.com/cve/CVE-2011-4599.html" source="CVE"/>
        <description>Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:16.771-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:55.543-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:59.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23739 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:59.834-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109688"/>
            <criterion comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109227"/>
            <criterion comment="libicu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109625"/>
            <criterion comment="icu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libicu-devel is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:109453"/>
            <criterion comment="libicu-doc is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:109692"/>
            <criterion comment="libicu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:109600"/>
            <criterion comment="icu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:108749"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23733" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0324: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:0324-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0324.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0841" ref_url="http://linux.oracle.com/cve/CVE-2012-0841.html" source="CVE"/>
        <description>libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:06.660-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.934-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:58.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23733 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.858-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:109811"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:109842"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:109157"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109220"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109422"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109737"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109945"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23731" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0869: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0869-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0869.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2110" ref_url="http://linux.oracle.com/cve/CVE-2011-2110.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:16.846-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.776-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:58.428-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23731 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.782-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el5" test_ref="oval:org.mitre.oval:tst:108641"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el6" test_ref="oval:org.mitre.oval:tst:108967"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23730" version="61" class="patch">
      <metadata>
        <title>ELSA-2011:1144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1144-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1144.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2130" ref_url="http://linux.oracle.com/cve/CVE-2011-2130.html" source="CVE"/>
        <reference ref_id="CVE-2011-2134" ref_url="http://linux.oracle.com/cve/CVE-2011-2134.html" source="CVE"/>
        <reference ref_id="CVE-2011-2135" ref_url="http://linux.oracle.com/cve/CVE-2011-2135.html" source="CVE"/>
        <reference ref_id="CVE-2011-2136" ref_url="http://linux.oracle.com/cve/CVE-2011-2136.html" source="CVE"/>
        <reference ref_id="CVE-2011-2137" ref_url="http://linux.oracle.com/cve/CVE-2011-2137.html" source="CVE"/>
        <reference ref_id="CVE-2011-2138" ref_url="http://linux.oracle.com/cve/CVE-2011-2138.html" source="CVE"/>
        <reference ref_id="CVE-2011-2139" ref_url="http://linux.oracle.com/cve/CVE-2011-2139.html" source="CVE"/>
        <reference ref_id="CVE-2011-2140" ref_url="http://linux.oracle.com/cve/CVE-2011-2140.html" source="CVE"/>
        <reference ref_id="CVE-2011-2414" ref_url="http://linux.oracle.com/cve/CVE-2011-2414.html" source="CVE"/>
        <reference ref_id="CVE-2011-2415" ref_url="http://linux.oracle.com/cve/CVE-2011-2415.html" source="CVE"/>
        <reference ref_id="CVE-2011-2416" ref_url="http://linux.oracle.com/cve/CVE-2011-2416.html" source="CVE"/>
        <reference ref_id="CVE-2011-2417" ref_url="http://linux.oracle.com/cve/CVE-2011-2417.html" source="CVE"/>
        <reference ref_id="CVE-2011-2424" ref_url="http://linux.oracle.com/cve/CVE-2011-2424.html" source="CVE"/>
        <reference ref_id="CVE-2011-2425" ref_url="http://linux.oracle.com/cve/CVE-2011-2425.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135, CVE-2011-2140, and CVE-2011-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:09.959-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.667-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23730 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:58.163-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.228-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el5" test_ref="oval:org.mitre.oval:tst:109242"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el6" test_ref="oval:org.mitre.oval:tst:109186"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23729" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0426: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0426-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0426.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0884" ref_url="http://linux.oracle.com/cve/CVE-2012-0884.html" source="CVE"/>
        <reference ref_id="CVE-2012-1165" ref_url="http://linux.oracle.com/cve/CVE-2012-1165.html" source="CVE"/>
        <description>The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:07.988-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.516-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23729 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:57.058-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:109748"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:109588"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:109759"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:109723"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:109838"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:110081"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:109985"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23728" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0468: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2012:0468-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0468.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1173" ref_url="http://linux.oracle.com/cve/CVE-2012-1173.html" source="CVE"/>
        <description>Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:16.465-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.436-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.554-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23728 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.725-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.025-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:110149"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:109975"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:109878"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:110035"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:110123"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23725" version="33" class="patch">
      <metadata>
        <title>ELSA-2011:1087: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1087-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1087.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:09.511-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.036-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.010-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23725 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.932-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:16.567-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109155"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108880"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109149"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108666"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108566"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109041"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108902"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108826"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108993"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109112"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109152"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109010"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108639"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108227"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23721" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0983: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0983-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0983.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2174" ref_url="http://linux.oracle.com/cve/CVE-2013-2174.html" source="CVE"/>
        <description>Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:57.619-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.858-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:56.751-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23721 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.792-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:16.286-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:111925"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:111504"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:112249"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:112229"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:111617"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23717" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1437: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1437-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1437.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3647" ref_url="http://linux.oracle.com/cve/CVE-2011-3647.html" source="CVE"/>
        <reference ref_id="CVE-2011-3648" ref_url="http://linux.oracle.com/cve/CVE-2011-3648.html" source="CVE"/>
        <reference ref_id="CVE-2011-3650" ref_url="http://linux.oracle.com/cve/CVE-2011-3650.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:59.097-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.348-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:55.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23717 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.529-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:15.645-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:109551"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:109435"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el5_7" test_ref="oval:org.mitre.oval:tst:109277"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109400"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109268"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el6_1" test_ref="oval:org.mitre.oval:tst:109534"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23712" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0685: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference ref_id="ELSA-2013:0685-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0685.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5195" ref_url="http://linux.oracle.com/cve/CVE-2012-5195.html" source="CVE"/>
        <reference ref_id="CVE-2012-5526" ref_url="http://linux.oracle.com/cve/CVE-2012-5526.html" source="CVE"/>
        <reference ref_id="CVE-2012-6329" ref_url="http://linux.oracle.com/cve/CVE-2012-6329.html" source="CVE"/>
        <reference ref_id="CVE-2013-1667" ref_url="http://linux.oracle.com/cve/CVE-2013-1667.html" source="CVE"/>
        <description>The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:49.246-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:52.538-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:54.630-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23712 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.110-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:14.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-libs is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111851"/>
            <criterion comment="perl-suidperl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111793"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111779"/>
            <criterion comment="perl-Package-Constants is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:111945"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:111934"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111678"/>
            <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:111765"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:111882"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:111830"/>
            <criterion comment="perl-Archive-Extract is earlier than 1:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:111970"/>
            <criterion comment="perl-version is earlier than 3:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:111359"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:111679"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:111408"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 1:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111396"/>
            <criterion comment="perl-Module-Loaded is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:111753"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111961"/>
            <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:111663"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:111941"/>
            <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:111457"/>
            <criterion comment="perl-parent is earlier than 1:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:111771"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111546"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:111933"/>
            <criterion comment="perl-Pod-Simple is earlier than 1:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:111498"/>
            <criterion comment="perl-Module-Load is earlier than 1:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:111974"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:111887"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:111967"/>
            <criterion comment="perl-IO-Zlib is earlier than 1:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:111944"/>
            <criterion comment="perl-Params-Check is earlier than 1:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:111623"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111399"/>
            <criterion comment="perl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111354"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:111656"/>
            <criterion comment="perl-Digest-SHA is earlier than 1:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:111402"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:111906"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:111778"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:111746"/>
            <criterion comment="perl-devel is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111907"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:111942"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:111972"/>
            <criterion comment="perl-Module-Build is earlier than 1:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:111875"/>
            <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:111084"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:111472"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:111810"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:111966"/>
            <criterion comment="perl-Object-Accessor is earlier than 1:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:111904"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111900"/>
            <criterion comment="perl-Log-Message is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:111583"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:111971"/>
            <criterion comment="perl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:111744"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23711" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0317: libpng security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference ref_id="ELSA-2012:0317-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0317.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3026" ref_url="http://linux.oracle.com/cve/CVE-2011-3026.html" source="CVE"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:13.988-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:52.454-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:54.478-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23711 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.647-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:14.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-static is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:110021"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:110099"/>
            <criterion comment="libpng is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:110045"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:109674"/>
            <criterion comment="libpng is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:110015"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23704" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0518: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference ref_id="ELSA-2012:0518-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0518.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2110" ref_url="http://linux.oracle.com/cve/CVE-2012-2110.html" source="CVE"/>
        <description>The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:16.601-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.717-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:53.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23704 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.686-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:109721"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:109933"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:110028"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" test_ref="oval:org.mitre.oval:tst:109212"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:109582"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:110124"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:109820"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:110024"/>
            <criterion comment="openssl098e is earlier than 0:0.9.8e-17.el6_2.2" test_ref="oval:org.mitre.oval:tst:109295"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23699" version="12" class="patch">
      <metadata>
        <title>ELSA-2014:0249: postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2014:0249-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0249.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0060" ref_url="http://linux.oracle.com/cve/CVE-2014-0060.html" source="CVE"/>
        <reference ref_id="CVE-2014-0061" ref_url="http://linux.oracle.com/cve/CVE-2014-0061.html" source="CVE"/>
        <reference ref_id="CVE-2014-0062" ref_url="http://linux.oracle.com/cve/CVE-2014-0062.html" source="CVE"/>
        <reference ref_id="CVE-2014-0063" ref_url="http://linux.oracle.com/cve/CVE-2014-0063.html" source="CVE"/>
        <reference ref_id="CVE-2014-0064" ref_url="http://linux.oracle.com/cve/CVE-2014-0064.html" source="CVE"/>
        <reference ref_id="CVE-2014-0065" ref_url="http://linux.oracle.com/cve/CVE-2014-0065.html" source="CVE"/>
        <reference ref_id="CVE-2014-0066" ref_url="http://linux.oracle.com/cve/CVE-2014-0066.html" source="CVE"/>
        <description>The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:45.157-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:05:52.172-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:08.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23699 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:20.094-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:01.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113309"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113569"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113148"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113562"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113498"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:112928"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113513"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113454"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113532"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-10.el5_10" test_ref="oval:org.mitre.oval:tst:113246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23698" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0731: expat security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>expat</product>
        </affected>
        <reference ref_id="ELSA-2012:0731-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0731.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0876" ref_url="http://linux.oracle.com/cve/CVE-2012-0876.html" source="CVE"/>
        <reference ref_id="CVE-2012-1148" ref_url="http://linux.oracle.com/cve/CVE-2012-1148.html" source="CVE"/>
        <description>Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:41.331-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.024-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:52.023-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23698 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.374-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="expat-devel is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:109508"/>
            <criterion comment="expat is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:110102"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="expat-devel is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:109583"/>
            <criterion comment="expat is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:110502"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23694" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0011: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2012:0011-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0011.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2462" ref_url="http://linux.oracle.com/cve/CVE-2011-2462.html" source="CVE"/>
        <reference ref_id="CVE-2011-4369" ref_url="http://linux.oracle.com/cve/CVE-2011-4369.html" source="CVE"/>
        <description>Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:08.549-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:50.532-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:51.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23694 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.233-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:109271"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:109602"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:109590"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:109216"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23687" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0270: jakarta-commons-httpclient security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference ref_id="ELSA-2013:0270-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0270.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5783" ref_url="http://linux.oracle.com/cve/CVE-2012-5783.html" source="CVE"/>
        <description>Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:27.395-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.776-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:50.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23687 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.606-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:11.907-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:111410"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:111388"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:110947"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:111284"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:111463"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:111101"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:110903"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:111073"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23686" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1164: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1164-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1164.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0084" ref_url="http://linux.oracle.com/cve/CVE-2011-0084.html" source="CVE"/>
        <reference ref_id="CVE-2011-2378" ref_url="http://linux.oracle.com/cve/CVE-2011-2378.html" source="CVE"/>
        <reference ref_id="CVE-2011-2981" ref_url="http://linux.oracle.com/cve/CVE-2011-2981.html" source="CVE"/>
        <reference ref_id="CVE-2011-2982" ref_url="http://linux.oracle.com/cve/CVE-2011-2982.html" source="CVE"/>
        <reference ref_id="CVE-2011-2983" ref_url="http://linux.oracle.com/cve/CVE-2011-2983.html" source="CVE"/>
        <reference ref_id="CVE-2011-2984" ref_url="http://linux.oracle.com/cve/CVE-2011-2984.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:21.826-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.592-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:49.937-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23686 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.901-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:11.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:109163"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:109104"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el5" test_ref="oval:org.mitre.oval:tst:109261"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:109066"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:108664"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:109096"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23684" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1458: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2011:1458-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1458.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4313" ref_url="http://linux.oracle.com/cve/CVE-2011-4313.html" source="CVE"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:09.393-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.430-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:49.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23684 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.712-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:11.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109676"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109550"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109294"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109548"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109705"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109539"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109528"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109642"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109385"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109719"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109573"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109682"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109546"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109596"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23676" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0699: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0699-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0699.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2333" ref_url="http://linux.oracle.com/cve/CVE-2012-2333.html" source="CVE"/>
        <description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:22.045-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:47.993-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:47.009-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23676 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.709-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:09.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:110216"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:110245"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:110148"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:110203"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:110048"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:109855"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:109777"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23671" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0434: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0434-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0434.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0773" ref_url="http://linux.oracle.com/cve/CVE-2012-0773.html" source="CVE"/>
        <description>The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:19.079-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.921-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.903-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23671 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.816-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.535-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el5" test_ref="oval:org.mitre.oval:tst:110131"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el6" test_ref="oval:org.mitre.oval:tst:109892"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23664" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1333: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1333-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1333.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2426" ref_url="http://linux.oracle.com/cve/CVE-2011-2426.html" source="CVE"/>
        <reference ref_id="CVE-2011-2427" ref_url="http://linux.oracle.com/cve/CVE-2011-2427.html" source="CVE"/>
        <reference ref_id="CVE-2011-2428" ref_url="http://linux.oracle.com/cve/CVE-2011-2428.html" source="CVE"/>
        <reference ref_id="CVE-2011-2429" ref_url="http://linux.oracle.com/cve/CVE-2011-2429.html" source="CVE"/>
        <reference ref_id="CVE-2011-2430" ref_url="http://linux.oracle.com/cve/CVE-2011-2430.html" source="CVE"/>
        <reference ref_id="CVE-2011-2444" ref_url="http://linux.oracle.com/cve/CVE-2011-2444.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:08.423-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.279-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.099-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23664 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.494-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" test_ref="oval:org.mitre.oval:tst:109320"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" test_ref="oval:org.mitre.oval:tst:109313"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23660" version="53" class="patch">
      <metadata>
        <title>ELSA-2012:0516: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0516-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0516.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3062" ref_url="http://linux.oracle.com/cve/CVE-2011-3062.html" source="CVE"/>
        <reference ref_id="CVE-2012-0467" ref_url="http://linux.oracle.com/cve/CVE-2012-0467.html" source="CVE"/>
        <reference ref_id="CVE-2012-0468" ref_url="http://linux.oracle.com/cve/CVE-2012-0468.html" source="CVE"/>
        <reference ref_id="CVE-2012-0469" ref_url="http://linux.oracle.com/cve/CVE-2012-0469.html" source="CVE"/>
        <reference ref_id="CVE-2012-0470" ref_url="http://linux.oracle.com/cve/CVE-2012-0470.html" source="CVE"/>
        <reference ref_id="CVE-2012-0471" ref_url="http://linux.oracle.com/cve/CVE-2012-0471.html" source="CVE"/>
        <reference ref_id="CVE-2012-0472" ref_url="http://linux.oracle.com/cve/CVE-2012-0472.html" source="CVE"/>
        <reference ref_id="CVE-2012-0473" ref_url="http://linux.oracle.com/cve/CVE-2012-0473.html" source="CVE"/>
        <reference ref_id="CVE-2012-0474" ref_url="http://linux.oracle.com/cve/CVE-2012-0474.html" source="CVE"/>
        <reference ref_id="CVE-2012-0477" ref_url="http://linux.oracle.com/cve/CVE-2012-0477.html" source="CVE"/>
        <reference ref_id="CVE-2012-0478" ref_url="http://linux.oracle.com/cve/CVE-2012-0478.html" source="CVE"/>
        <reference ref_id="CVE-2012-0479" ref_url="http://linux.oracle.com/cve/CVE-2012-0479.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:27.970-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:45.676-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:43.173-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23660 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.759-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:07.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:110068"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:109913"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23659" version="173" class="patch">
      <metadata>
        <title>ELSA-2011:1434: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2011:1434-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1434.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2094" ref_url="http://linux.oracle.com/cve/CVE-2011-2094.html" source="CVE"/>
        <reference ref_id="CVE-2011-2095" ref_url="http://linux.oracle.com/cve/CVE-2011-2095.html" source="CVE"/>
        <reference ref_id="CVE-2011-2096" ref_url="http://linux.oracle.com/cve/CVE-2011-2096.html" source="CVE"/>
        <reference ref_id="CVE-2011-2097" ref_url="http://linux.oracle.com/cve/CVE-2011-2097.html" source="CVE"/>
        <reference ref_id="CVE-2011-2098" ref_url="http://linux.oracle.com/cve/CVE-2011-2098.html" source="CVE"/>
        <reference ref_id="CVE-2011-2099" ref_url="http://linux.oracle.com/cve/CVE-2011-2099.html" source="CVE"/>
        <reference ref_id="CVE-2011-2101" ref_url="http://linux.oracle.com/cve/CVE-2011-2101.html" source="CVE"/>
        <reference ref_id="CVE-2011-2104" ref_url="http://linux.oracle.com/cve/CVE-2011-2104.html" source="CVE"/>
        <reference ref_id="CVE-2011-2105" ref_url="http://linux.oracle.com/cve/CVE-2011-2105.html" source="CVE"/>
        <reference ref_id="CVE-2011-2107" ref_url="http://linux.oracle.com/cve/CVE-2011-2107.html" source="CVE"/>
        <reference ref_id="CVE-2011-2130" ref_url="http://linux.oracle.com/cve/CVE-2011-2130.html" source="CVE"/>
        <reference ref_id="CVE-2011-2134" ref_url="http://linux.oracle.com/cve/CVE-2011-2134.html" source="CVE"/>
        <reference ref_id="CVE-2011-2135" ref_url="http://linux.oracle.com/cve/CVE-2011-2135.html" source="CVE"/>
        <reference ref_id="CVE-2011-2136" ref_url="http://linux.oracle.com/cve/CVE-2011-2136.html" source="CVE"/>
        <reference ref_id="CVE-2011-2137" ref_url="http://linux.oracle.com/cve/CVE-2011-2137.html" source="CVE"/>
        <reference ref_id="CVE-2011-2138" ref_url="http://linux.oracle.com/cve/CVE-2011-2138.html" source="CVE"/>
        <reference ref_id="CVE-2011-2139" ref_url="http://linux.oracle.com/cve/CVE-2011-2139.html" source="CVE"/>
        <reference ref_id="CVE-2011-2140" ref_url="http://linux.oracle.com/cve/CVE-2011-2140.html" source="CVE"/>
        <reference ref_id="CVE-2011-2414" ref_url="http://linux.oracle.com/cve/CVE-2011-2414.html" source="CVE"/>
        <reference ref_id="CVE-2011-2415" ref_url="http://linux.oracle.com/cve/CVE-2011-2415.html" source="CVE"/>
        <reference ref_id="CVE-2011-2416" ref_url="http://linux.oracle.com/cve/CVE-2011-2416.html" source="CVE"/>
        <reference ref_id="CVE-2011-2417" ref_url="http://linux.oracle.com/cve/CVE-2011-2417.html" source="CVE"/>
        <reference ref_id="CVE-2011-2424" ref_url="http://linux.oracle.com/cve/CVE-2011-2424.html" source="CVE"/>
        <reference ref_id="CVE-2011-2425" ref_url="http://linux.oracle.com/cve/CVE-2011-2425.html" source="CVE"/>
        <reference ref_id="CVE-2011-2426" ref_url="http://linux.oracle.com/cve/CVE-2011-2426.html" source="CVE"/>
        <reference ref_id="CVE-2011-2427" ref_url="http://linux.oracle.com/cve/CVE-2011-2427.html" source="CVE"/>
        <reference ref_id="CVE-2011-2428" ref_url="http://linux.oracle.com/cve/CVE-2011-2428.html" source="CVE"/>
        <reference ref_id="CVE-2011-2429" ref_url="http://linux.oracle.com/cve/CVE-2011-2429.html" source="CVE"/>
        <reference ref_id="CVE-2011-2430" ref_url="http://linux.oracle.com/cve/CVE-2011-2430.html" source="CVE"/>
        <reference ref_id="CVE-2011-2431" ref_url="http://linux.oracle.com/cve/CVE-2011-2431.html" source="CVE"/>
        <reference ref_id="CVE-2011-2432" ref_url="http://linux.oracle.com/cve/CVE-2011-2432.html" source="CVE"/>
        <reference ref_id="CVE-2011-2433" ref_url="http://linux.oracle.com/cve/CVE-2011-2433.html" source="CVE"/>
        <reference ref_id="CVE-2011-2434" ref_url="http://linux.oracle.com/cve/CVE-2011-2434.html" source="CVE"/>
        <reference ref_id="CVE-2011-2435" ref_url="http://linux.oracle.com/cve/CVE-2011-2435.html" source="CVE"/>
        <reference ref_id="CVE-2011-2436" ref_url="http://linux.oracle.com/cve/CVE-2011-2436.html" source="CVE"/>
        <reference ref_id="CVE-2011-2437" ref_url="http://linux.oracle.com/cve/CVE-2011-2437.html" source="CVE"/>
        <reference ref_id="CVE-2011-2438" ref_url="http://linux.oracle.com/cve/CVE-2011-2438.html" source="CVE"/>
        <reference ref_id="CVE-2011-2439" ref_url="http://linux.oracle.com/cve/CVE-2011-2439.html" source="CVE"/>
        <reference ref_id="CVE-2011-2440" ref_url="http://linux.oracle.com/cve/CVE-2011-2440.html" source="CVE"/>
        <reference ref_id="CVE-2011-2442" ref_url="http://linux.oracle.com/cve/CVE-2011-2442.html" source="CVE"/>
        <reference ref_id="CVE-2011-2444" ref_url="http://linux.oracle.com/cve/CVE-2011-2444.html" source="CVE"/>
        <reference ref_id="CVE-2011-4374" ref_url="http://linux.oracle.com/cve/CVE-2011-4374.html" source="CVE"/>
        <description>Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:56.435-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.838-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:41.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23659 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.433-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:06.260-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:109073"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:109518"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:109196"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:109129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23656" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0934: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2010:0934-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0934.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3654" ref_url="http://linux.oracle.com/cve/CVE-2010-3654.html" source="CVE"/>
        <reference ref_id="CVE-2010-4091" ref_url="http://linux.oracle.com/cve/CVE-2010-4091.html" source="CVE"/>
        <description>The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:30.064-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.496-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.741-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23656 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.603-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:108034"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:107655"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:107969"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:107774"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23652" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:0374: thunderbird security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0374-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0374.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
This erratum blacklists a small number of HTTPS certificates. (BZ#689430)
This update also fixes the following bug:
* The RHSA-2011:0312 and RHSA-2011:0311 updates introduced a regression,
preventing some Java content and plug-ins written in Java from loading.
With this update, the Java content and plug-ins work as expected.
(BZ#683076)
All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:21.077-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.220-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.306-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23652 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.351-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.387-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-15.el5_6" test_ref="oval:org.mitre.oval:tst:108510"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.9-3.el6_0" test_ref="oval:org.mitre.oval:tst:108013"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23649" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0174: piranha security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>piranha</product>
        </affected>
        <reference ref_id="ELSA-2014:0174-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0174.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6492" ref_url="http://linux.oracle.com/cve/CVE-2013-6492.html" source="CVE"/>
        <description>The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:06.775-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:43.568-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:39.039-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23649 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.001-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:04.433-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="piranha is earlier than 0:0.8.4-26.el5_10.1" test_ref="oval:org.mitre.oval:tst:108064"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23647" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0465: samba security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2012:0465-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0465.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1182" ref_url="http://linux.oracle.com/cve/CVE-2012-1182.html" source="CVE"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:02.643-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.968-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:38.002-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23647 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.703-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:110120"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:109635"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:110161"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:109969"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:110016"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:109983"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109978"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109982"/>
            <criterion comment="samba is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109586"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109869"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109832"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109858"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109576"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:110079"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:110082"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109358"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109571"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109799"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23646" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1804: libjpeg security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libjpeg</product>
        </affected>
        <reference ref_id="ELSA-2013:1804-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1804.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <description>The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:38.940-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.902-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:37.898-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23646 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.274-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.582-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libjpeg-devel is earlier than 0:6b-38" test_ref="oval:org.mitre.oval:tst:107699"/>
          <criterion comment="libjpeg is earlier than 0:6b-38" test_ref="oval:org.mitre.oval:tst:107961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23643" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1363: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1363-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1363.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5166" ref_url="http://linux.oracle.com/cve/CVE-2012-5166.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:07.633-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.660-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:37.571-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23643 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:21.498-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.271-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110916"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110599"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:111098"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110484"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110470"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:111135"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110955"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:111042"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110962"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:111216"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110869"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110726"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110702"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110859"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23641" version="58" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0097: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0097-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0097.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:08.067-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.291-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:36.903-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23641 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.266-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:02.796-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:54:43.542-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:54:43.542-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107985"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107833"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107975"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107286"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:108054"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107190"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107809"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107867"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:108016"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107270"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23639" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1187: dovecot security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference ref_id="ELSA-2011:1187-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1187.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1929" ref_url="http://linux.oracle.com/cve/CVE-2011-1929.html" source="CVE"/>
        <description>lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:21.309-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.081-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:36.583-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23639 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:10.925-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:02.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="dovecot is earlier than 0:1.0.7-7.el5_7.1" test_ref="oval:org.mitre.oval:tst:108428"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109169"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109177"/>
            <criterion comment="dovecot is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:108652"/>
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109308"/>
            <criterion comment="dovecot-devel is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109254"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23634" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0108: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2014:0108-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0108.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4494" ref_url="http://linux.oracle.com/cve/CVE-2013-4494.html" source="CVE"/>
        <description>Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:10.044-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:41.251-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:35.190-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23634 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:06.431-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:01.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107970"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107997"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107939"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107955"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107879"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107850"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107925"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107953"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107802"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107859"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107682"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.4.1.el5" test_ref="oval:org.mitre.oval:tst:107684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23630" version="49" class="patch">
      <metadata>
        <title>ELSA-2011:1445: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1445-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1445.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2445" ref_url="http://linux.oracle.com/cve/CVE-2011-2445.html" source="CVE"/>
        <reference ref_id="CVE-2011-2450" ref_url="http://linux.oracle.com/cve/CVE-2011-2450.html" source="CVE"/>
        <reference ref_id="CVE-2011-2451" ref_url="http://linux.oracle.com/cve/CVE-2011-2451.html" source="CVE"/>
        <reference ref_id="CVE-2011-2452" ref_url="http://linux.oracle.com/cve/CVE-2011-2452.html" source="CVE"/>
        <reference ref_id="CVE-2011-2453" ref_url="http://linux.oracle.com/cve/CVE-2011-2453.html" source="CVE"/>
        <reference ref_id="CVE-2011-2454" ref_url="http://linux.oracle.com/cve/CVE-2011-2454.html" source="CVE"/>
        <reference ref_id="CVE-2011-2455" ref_url="http://linux.oracle.com/cve/CVE-2011-2455.html" source="CVE"/>
        <reference ref_id="CVE-2011-2456" ref_url="http://linux.oracle.com/cve/CVE-2011-2456.html" source="CVE"/>
        <reference ref_id="CVE-2011-2457" ref_url="http://linux.oracle.com/cve/CVE-2011-2457.html" source="CVE"/>
        <reference ref_id="CVE-2011-2459" ref_url="http://linux.oracle.com/cve/CVE-2011-2459.html" source="CVE"/>
        <reference ref_id="CVE-2011-2460" ref_url="http://linux.oracle.com/cve/CVE-2011-2460.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:05.840-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.464-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:34.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23630 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.126-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el5" test_ref="oval:org.mitre.oval:tst:108718"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el6" test_ref="oval:org.mitre.oval:tst:109647"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23626" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1385: kdelibs and kdelibs3 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
          <product>kdelibs3</product>
        </affected>
        <reference ref_id="ELSA-2011:1385-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1385.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3365" ref_url="http://linux.oracle.com/cve/CVE-2011-3365.html" source="CVE"/>
        <description>The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:54.967-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.137-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23626 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.998-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.363-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:109481"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:108507"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:109056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="kdelibs3-apidocs is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:109343"/>
            <criterion comment="kdelibs3-devel is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:109278"/>
            <criterion comment="kdelibs3 is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:109454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23621" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0018: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference ref_id="ELSA-2014:0018-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0018.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6462" ref_url="http://linux.oracle.com/cve/CVE-2013-6462.html" source="CVE"/>
        <description>Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:07.233-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:39.336-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:32.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23621 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:10.620-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:59.495-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:53:45.260-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:53:45.260-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:107053"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:107841"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:108010"/>
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:107811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23618" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0950: apr-util security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr-util</product>
        </affected>
        <reference ref_id="ELSA-2010:0950-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0950.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1623" ref_url="http://linux.oracle.com/cve/CVE-2010-1623.html" source="CVE"/>
        <description>Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:37.990-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.915-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:31.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23618 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:11.273-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.931-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:108022"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:107888"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:108241"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:108151"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108239"/>
            <criterion comment="apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108117"/>
            <criterion comment="apr-util-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108225"/>
            <criterion comment="apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108186"/>
            <criterion comment="apr-util is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107924"/>
            <criterion comment="apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108057"/>
            <criterion comment="apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107998"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23617" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1455: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2011:1455-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1455.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3439" ref_url="http://linux.oracle.com/cve/CVE-2011-3439.html" source="CVE"/>
        <description>FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:54.336-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.839-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:31.479-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23617 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.043-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:109525"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:109630"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:109500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:109089"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:109145"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:109618"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23615" version="81" class="patch">
      <metadata>
        <title>ELSA-2011:0282: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2011:0282-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0282.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4422" ref_url="http://linux.oracle.com/cve/CVE-2010-4422.html" source="CVE"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4450" ref_url="http://linux.oracle.com/cve/CVE-2010-4450.html" source="CVE"/>
        <reference ref_id="CVE-2010-4451" ref_url="http://linux.oracle.com/cve/CVE-2010-4451.html" source="CVE"/>
        <reference ref_id="CVE-2010-4452" ref_url="http://linux.oracle.com/cve/CVE-2010-4452.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4463" ref_url="http://linux.oracle.com/cve/CVE-2010-4463.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4467" ref_url="http://linux.oracle.com/cve/CVE-2010-4467.html" source="CVE"/>
        <reference ref_id="CVE-2010-4468" ref_url="http://linux.oracle.com/cve/CVE-2010-4468.html" source="CVE"/>
        <reference ref_id="CVE-2010-4469" ref_url="http://linux.oracle.com/cve/CVE-2010-4469.html" source="CVE"/>
        <reference ref_id="CVE-2010-4470" ref_url="http://linux.oracle.com/cve/CVE-2010-4470.html" source="CVE"/>
        <reference ref_id="CVE-2010-4471" ref_url="http://linux.oracle.com/cve/CVE-2010-4471.html" source="CVE"/>
        <reference ref_id="CVE-2010-4472" ref_url="http://linux.oracle.com/cve/CVE-2010-4472.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:33.033-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.236-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:30.899-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23615 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.505-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108216"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108372"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108533"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:107761"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108581"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108582"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108622"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108534"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108210"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108339"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108261"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108445"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23613" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1256: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference ref_id="ELSA-2012:1256-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1256.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4405" ref_url="http://linux.oracle.com/cve/CVE-2012-4405.html" source="CVE"/>
        <description>Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow.  NOTE: this issue is also described as an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:37.294-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.081-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:30.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23613 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:12.272-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:111009"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:110945"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:111043"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110163"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110911"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110959"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110704"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23610" version="33" class="patch">
      <metadata>
        <title>ELSA-2012:0469: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2012:0469-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0469.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4370" ref_url="http://linux.oracle.com/cve/CVE-2011-4370.html" source="CVE"/>
        <reference ref_id="CVE-2011-4371" ref_url="http://linux.oracle.com/cve/CVE-2011-4371.html" source="CVE"/>
        <reference ref_id="CVE-2011-4372" ref_url="http://linux.oracle.com/cve/CVE-2011-4372.html" source="CVE"/>
        <reference ref_id="CVE-2011-4373" ref_url="http://linux.oracle.com/cve/CVE-2011-4373.html" source="CVE"/>
        <reference ref_id="CVE-2012-0774" ref_url="http://linux.oracle.com/cve/CVE-2012-0774.html" source="CVE"/>
        <reference ref_id="CVE-2012-0775" ref_url="http://linux.oracle.com/cve/CVE-2012-0775.html" source="CVE"/>
        <reference ref_id="CVE-2012-0777" ref_url="http://linux.oracle.com/cve/CVE-2012-0777.html" source="CVE"/>
        <description>The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:18.126-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.618-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:29.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23610 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:05.707-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:110135"/>
            <criterion comment="acroread is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:109594"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:109448"/>
            <criterion comment="acroread is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:109981"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23609" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1123: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1123-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1123.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3817" ref_url="http://linux.oracle.com/cve/CVE-2012-3817.html" source="CVE"/>
        <description>ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:38.071-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.524-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:29.597-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23609 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:07.896-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110762"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110530"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110424"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110498"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110806"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110773"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:109825"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110241"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110731"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110819"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110772"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110619"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110464"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110496"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23607" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0844: apr security update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference ref_id="ELSA-2011:0844-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0844.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1928" ref_url="http://linux.oracle.com/cve/CVE-2011-1928.html" source="CVE"/>
        <description>The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used.  NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:40.980-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.327-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:29.260-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23607 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.885-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:108649"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:109008"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:108834"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:108912"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:108886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23604" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1474: qspice security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>qspice</product>
        </affected>
        <reference ref_id="ELSA-2013:1474-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1474.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4282" ref_url="http://linux.oracle.com/cve/CVE-2013-4282.html" source="CVE"/>
        <description>Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:33.624-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.849-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:28.722-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23604 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.720-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:56.550-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qspice-libs-devel is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:107362"/>
          <criterion comment="qspice is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:107508"/>
          <criterion comment="qspice-libs is earlier than 0:0.3.0-56.el5_10.1" test_ref="oval:org.mitre.oval:tst:107411"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23601" version="45" class="patch">
      <metadata>
        <title>ELSA-2011:0938: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0938-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0938.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0863" ref_url="http://linux.oracle.com/cve/CVE-2011-0863.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0868" ref_url="http://linux.oracle.com/cve/CVE-2011-0868.html" source="CVE"/>
        <reference ref_id="CVE-2011-0869" ref_url="http://linux.oracle.com/cve/CVE-2011-0869.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:19.928-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.482-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23601 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:05.858-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:56.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109059"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109088"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108969"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109042"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109154"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109117"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108648"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109035"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109019"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109013"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109111"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109084"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109085"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108219"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23598" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0359: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0359-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0359.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0768" ref_url="http://linux.oracle.com/cve/CVE-2012-0768.html" source="CVE"/>
        <reference ref_id="CVE-2012-0769" ref_url="http://linux.oracle.com/cve/CVE-2012-0769.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obtain sensitive information via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:10.977-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.070-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.128-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23598 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:11.593-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:55.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el5" test_ref="oval:org.mitre.oval:tst:109164"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el6" test_ref="oval:org.mitre.oval:tst:109970"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23597" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0627: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0627-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0627.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0787" ref_url="http://linux.oracle.com/cve/CVE-2013-0787.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:40.170-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:35.965-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.016-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23597 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:10.120-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:55.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:111449"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:111675"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23595" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0291: java-1.5.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0291-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0291.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:41.057-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.968-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:25.170-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23595 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:11.913-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:54.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108414"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108691"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108217"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108564"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108635"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108463"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108679"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108601"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108682"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108083"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108545"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108527"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108535"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108074"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23592" version="57" class="patch">
      <metadata>
        <title>ELSA-2011:0357: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0357-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0357.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4422" ref_url="http://linux.oracle.com/cve/CVE-2010-4422.html" source="CVE"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4452" ref_url="http://linux.oracle.com/cve/CVE-2010-4452.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4463" ref_url="http://linux.oracle.com/cve/CVE-2010-4463.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4467" ref_url="http://linux.oracle.com/cve/CVE-2010-4467.html" source="CVE"/>
        <reference ref_id="CVE-2010-4468" ref_url="http://linux.oracle.com/cve/CVE-2010-4468.html" source="CVE"/>
        <reference ref_id="CVE-2010-4471" ref_url="http://linux.oracle.com/cve/CVE-2010-4471.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:17.499-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.504-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:24.614-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23592 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:13.188-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108725"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108518"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108713"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108508"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108699"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108515"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108289"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108523"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108704"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108552"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108068"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108690"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108600"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108447"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23591" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1869: pixman security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference ref_id="ELSA-2013:1869-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1869.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6425" ref_url="http://linux.oracle.com/cve/CVE-2013-6425.html" source="CVE"/>
        <description>Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:35.781-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.435-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:24.472-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23591 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.233-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.551-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:53:07.736-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:53:07.736-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:107640"/>
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:107988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:107555"/>
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:107351"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23590" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0093: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0093-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0093.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0830" ref_url="http://linux.oracle.com/cve/CVE-2012-0830.html" source="CVE"/>
        <description>The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.	 NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:12.470-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.285-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:24.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23590 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:06.897-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109884"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109173"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109747"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109806"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109809"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109937"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109902"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109634"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109523"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109830"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109966"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109684"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109733"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109957"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109627"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109103"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109846"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109898"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109897"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109731"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109974"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109896"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:110007"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109350"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109979"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109687"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109722"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109962"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109808"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109856"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109987"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109544"/>
            <criterion comment="php is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:110037"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109847"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109626"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109324"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109844"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109917"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109968"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109703"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109411"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:110104"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109397"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109953"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23589" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0019: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0019-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0019.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4566" ref_url="http://linux.oracle.com/cve/CVE-2011-4566.html" source="CVE"/>
        <reference ref_id="CVE-2011-4885" ref_url="http://linux.oracle.com/cve/CVE-2011-4885.html" source="CVE"/>
        <description>PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:20.328-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.125-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:23.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23589 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:06.244-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.091-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109570"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:108792"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109696"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109287"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109432"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109601"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109139"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109217"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109469"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109668"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109477"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109595"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109021"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109706"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109118"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109768"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109574"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109739"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:108978"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109549"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109447"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109587"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109685"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109357"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109437"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109773"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109717"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109732"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109378"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109200"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109766"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109068"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109566"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109730"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109611"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109620"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109757"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109532"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109214"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109541"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109522"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109771"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:108870"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109195"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109445"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109608"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109756"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23587" version="121" class="patch">
      <metadata>
        <title>ELSA-2013:1447: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1447-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1447.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5800" ref_url="http://linux.oracle.com/cve/CVE-2013-5800.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5838" ref_url="http://linux.oracle.com/cve/CVE-2013-5838.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5851" ref_url="http://linux.oracle.com/cve/CVE-2013-5851.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:39.662-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.964-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:21.650-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23587 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:54.188-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:52.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:107806"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:107736"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:107702"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:107797"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.45-2.4.3.1.el5_10" test_ref="oval:org.mitre.oval:tst:106968"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23580" version="41" class="patch">
      <metadata>
        <title>ELSA-2013:1823: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1823-04" ref_url="http://linux.oracle.com/errata/ELSA-2013-1823.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <reference ref_id="CVE-2013-6674" ref_url="http://linux.oracle.com/cve/CVE-2013-6674.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:24.585-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.360-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:20.619-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23580 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.957-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:51.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:108018"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:107576"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23579" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1263: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1263-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1263.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3488" ref_url="http://linux.oracle.com/cve/CVE-2012-3488.html" source="CVE"/>
        <reference ref_id="CVE-2012-3489" ref_url="http://linux.oracle.com/cve/CVE-2012-3489.html" source="CVE"/>
        <description>The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:40.637-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.237-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:20.414-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23579 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.295-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:51.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111177"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110965"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110291"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111129"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111058"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111182"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111088"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110802"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111077"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110850"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111192"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110818"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110553"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111062"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111206"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110844"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111028"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110791"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111044"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111163"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110706"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110699"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23575" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1861: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1861-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1861.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:29.558-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.941-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:19.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23575 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:54.032-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.558-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:52:29.946-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:52:29.946-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:107952"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:107397"/>
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:108047"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:107994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107669"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107898"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107724"/>
            <criterion comment="nss is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107729"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23574" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1243: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1243-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1243.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Thunderbird; however, affected certificates
issued after this date cannot be re-enabled or used. (BZ#734316)
All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:10.734-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.895-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:19.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23574 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.324-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-24.el5" test_ref="oval:org.mitre.oval:tst:109333"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.12-2.el6_1" test_ref="oval:org.mitre.oval:tst:109183"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23571" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0507: apr security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference ref_id="ELSA-2011:0507-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0507.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0419" ref_url="http://linux.oracle.com/cve/CVE-2011-0419.html" source="CVE"/>
        <description>Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:36.997-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.303-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:18.931-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23571 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.408-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:49.791-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:107865"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:108362"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:108785"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108409"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108847"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23570" version="42" class="patch">
      <metadata>
        <title>ELSA-2011:0364: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0364-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0364.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4450" ref_url="http://linux.oracle.com/cve/CVE-2010-4450.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4468" ref_url="http://linux.oracle.com/cve/CVE-2010-4468.html" source="CVE"/>
        <reference ref_id="CVE-2010-4471" ref_url="http://linux.oracle.com/cve/CVE-2010-4471.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:19.560-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.766-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:18.413-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23570 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.641-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:49.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108411"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108092"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108467"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108683"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108570"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108514"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108687"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108723"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108305"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108720"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:107799"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108728"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108627"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108578"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108128"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23565" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0321: cvs security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>cvs</product>
        </affected>
        <reference ref_id="ELSA-2012:0321-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0321.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0804" ref_url="http://linux.oracle.com/cve/CVE-2012-0804.html" source="CVE"/>
        <description>Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:01.824-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.094-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:17.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23565 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.786-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:48.409-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cvs-inetd is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:109994"/>
            <criterion comment="cvs is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:109939"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="cvs is earlier than 0:1.11.23-11.el6_2.1" test_ref="oval:org.mitre.oval:tst:109935"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23564" version="38" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1268: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1268-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1268.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1718" ref_url="http://linux.oracle.com/cve/CVE-2013-1718.html" source="CVE"/>
        <reference ref_id="CVE-2013-1722" ref_url="http://linux.oracle.com/cve/CVE-2013-1722.html" source="CVE"/>
        <reference ref_id="CVE-2013-1725" ref_url="http://linux.oracle.com/cve/CVE-2013-1725.html" source="CVE"/>
        <reference ref_id="CVE-2013-1730" ref_url="http://linux.oracle.com/cve/CVE-2013-1730.html" source="CVE"/>
        <reference ref_id="CVE-2013-1732" ref_url="http://linux.oracle.com/cve/CVE-2013-1732.html" source="CVE"/>
        <reference ref_id="CVE-2013-1735" ref_url="http://linux.oracle.com/cve/CVE-2013-1735.html" source="CVE"/>
        <reference ref_id="CVE-2013-1736" ref_url="http://linux.oracle.com/cve/CVE-2013-1736.html" source="CVE"/>
        <reference ref_id="CVE-2013-1737" ref_url="http://linux.oracle.com/cve/CVE-2013-1737.html" source="CVE"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:34.159-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:29.740-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:17.311-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23564 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.898-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:48.099-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:51:34.102-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:51:34.102-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:107739"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:107344"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:107789"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:107744"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:107780"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:107563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23561" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0185: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2014:0185-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0185.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6466" ref_url="http://linux.oracle.com/cve/CVE-2013-6466.html" source="CVE"/>
        <description>Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:07.378-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.825-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.389-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23561 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.541-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.457-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:50:49.362-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:50:49.362-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:107444"/>
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:108072"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:107716"/>
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:107126"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23559" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0165: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0165-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0165.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3174" ref_url="http://linux.oracle.com/cve/CVE-2012-3174.html" source="CVE"/>
        <reference ref_id="CVE-2013-0422" ref_url="http://linux.oracle.com/cve/CVE-2013-0422.html" source="CVE"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:20.278-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.634-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23559 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.085-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:110518"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:110392"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:111244"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:111184"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:111001"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:111075"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:111138"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:111038"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:110983"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:110438"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23558" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1132: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus</product>
        </affected>
        <reference ref_id="ELSA-2011:1132-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1132.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2200" ref_url="http://linux.oracle.com/cve/CVE-2011-2200.html" source="CVE"/>
        <description>The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:16.183-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.486-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.036-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23558 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.797-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.124-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:109249"/>
            <criterion comment="dbus is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:109213"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:109036"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:108701"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109115"/>
            <criterion comment="dbus is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109165"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109316"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109283"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109095"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23557" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1409: xinetd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference ref_id="ELSA-2013:1409-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1409.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4342" ref_url="http://linux.oracle.com/cve/CVE-2013-4342.html" source="CVE"/>
        <description>xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:38.227-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.387-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:15.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23557 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.306-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.005-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:50:11.441-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:50:11.441-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="xinetd is earlier than 2:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:107429"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xinetd is earlier than 2:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:107637"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23556" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0889: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2010:0889-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0889.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3855" ref_url="http://linux.oracle.com/cve/CVE-2010-3855.html" source="CVE"/>
        <description>Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:33.725-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.277-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:15.805-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23556 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.409-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:46.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:108024"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:108104"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:108080"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:107896"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:108125"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:107962"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23554" version="106" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1014: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1014-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1014.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.	NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:40.097-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:27.214-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:14.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23554 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.829-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:45.900-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:49:39.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:49:39.289-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107175"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107431"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107392"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107261"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:106701"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107218"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107161"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107500"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107040"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23553" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0705: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference ref_id="ELSA-2012:0705-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0705.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1149" ref_url="http://linux.oracle.com/cve/CVE-2012-1149.html" source="CVE"/>
        <reference ref_id="CVE-2012-2334" ref_url="http://linux.oracle.com/cve/CVE-2012-2334.html" source="CVE"/>
        <description>Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt) document, which triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:26.711-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:26.541-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:13.976-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23553 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:54.867-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:45.306-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109967"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110070"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109837"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109597"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109862"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110134"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110362"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110140"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110338"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110156"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110226"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110089"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110310"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110207"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110187"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110264"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110173"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110141"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110259"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110319"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110058"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110315"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109821"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109362"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110323"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110069"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110252"/>
            <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110129"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110302"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110211"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109885"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109823"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109961"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110325"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110256"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109984"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109814"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110026"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109833"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109751"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110029"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110300"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109365"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110294"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110288"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110355"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110257"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109786"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109593"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110205"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110182"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109787"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110042"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110128"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109656"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110233"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110044"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109971"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110208"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110107"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110318"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110331"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109749"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110073"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110176"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110115"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109995"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110352"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109864"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110307"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110239"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110088"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109440"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110077"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110322"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109710"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109887"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110334"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110033"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110456"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109459"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110349"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110147"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110416"/>
            <criterion comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109616"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110327"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110144"/>
            <criterion comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110414"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110269"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110036"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110380"/>
            <criterion comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110332"/>
            <criterion comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109407"/>
            <criterion comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110413"/>
            <criterion comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110305"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110340"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110460"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110125"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110087"/>
            <criterion comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109728"/>
            <criterion comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110261"/>
            <criterion comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109948"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110236"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109758"/>
            <criterion comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109801"/>
            <criterion comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110473"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110179"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110219"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110263"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110316"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110003"/>
            <criterion comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109926"/>
            <criterion comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110367"/>
            <criterion comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110412"/>
            <criterion comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109734"/>
            <criterion comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110346"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110321"/>
            <criterion comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110253"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110152"/>
            <criterion comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110356"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109936"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109956"/>
            <criterion comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110137"/>
            <criterion comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110366"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110393"/>
            <criterion comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110371"/>
            <criterion comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110227"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110353"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110250"/>
            <criterion comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110204"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109788"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110202"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109911"/>
            <criterion comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110407"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109907"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109505"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109708"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110243"/>
            <criterion comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110457"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110337"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110490"/>
            <criterion comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109988"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110299"/>
            <criterion comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109891"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110342"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110206"/>
            <criterion comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110223"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109563"/>
            <criterion comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110370"/>
            <criterion comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109419"/>
            <criterion comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110417"/>
            <criterion comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110374"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110385"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110232"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110271"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109408"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110471"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109889"/>
            <criterion comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110276"/>
            <criterion comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110439"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110265"/>
            <criterion comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110369"/>
            <criterion comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109871"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109491"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109529"/>
            <criterion comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109753"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110354"/>
            <criterion comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110475"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109476"/>
            <criterion comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110320"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109829"/>
            <criterion comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110397"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110284"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110192"/>
            <criterion comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110410"/>
            <criterion comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109854"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110185"/>
            <criterion comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110005"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110444"/>
            <criterion comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110377"/>
            <criterion comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109912"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110286"/>
            <criterion comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110343"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110390"/>
            <criterion comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110290"/>
            <criterion comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110053"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110363"/>
            <criterion comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110409"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109646"/>
            <criterion comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110330"/>
            <criterion comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110027"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110297"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110433"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109853"/>
            <criterion comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110449"/>
            <criterion comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110251"/>
            <criterion comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110279"/>
            <criterion comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110447"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110293"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109909"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110194"/>
            <criterion comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110396"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110268"/>
            <criterion comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110406"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110445"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109943"/>
            <criterion comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110295"/>
            <criterion comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110421"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110381"/>
            <criterion comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110228"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109951"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109746"/>
            <criterion comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110436"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23547" version="42" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1823: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1823-04" ref_url="http://linux.oracle.com/errata/ELSA-2013-1823.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <reference ref_id="CVE-2013-6674" ref_url="http://linux.oracle.com/cve/CVE-2013-6674.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:12.841-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:23.332-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:10.302-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23547 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.762-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:42.493-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:48:43.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:48:43.008-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:112789"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112383"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23541" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1349: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>rpm</product>
        </affected>
        <reference ref_id="ELSA-2011:1349-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1349.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3378" ref_url="http://linux.oracle.com/cve/CVE-2011-3378.html" source="CVE"/>
        <description>RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:08.274-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:22.174-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:09.044-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23541 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.398-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:41.493-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109387"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109076"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:108450"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:108779"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109181"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109374"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109052"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109338"/>
            <criterion comment="rpm is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109192"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109380"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:108424"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109234"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109366"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109263"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23537" version="33" class="patch">
      <metadata>
        <title>ELSA-2011:1478: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1478-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1478.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3545" ref_url="http://linux.oracle.com/cve/CVE-2011-3545.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3549" ref_url="http://linux.oracle.com/cve/CVE-2011-3549.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:53.172-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:21.469-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:08.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23537 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:54.358-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:40.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109536"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109615"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109507"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109038"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109504"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109704"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109718"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109677"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109643"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108876"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109503"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109681"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109603"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109017"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109423"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23532" version="49" class="patch">
      <metadata>
        <title>ELSA-2010:0966: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2010:0966-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0966.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3766" ref_url="http://linux.oracle.com/cve/CVE-2010-3766.html" source="CVE"/>
        <reference ref_id="CVE-2010-3767" ref_url="http://linux.oracle.com/cve/CVE-2010-3767.html" source="CVE"/>
        <reference ref_id="CVE-2010-3768" ref_url="http://linux.oracle.com/cve/CVE-2010-3768.html" source="CVE"/>
        <reference ref_id="CVE-2010-3770" ref_url="http://linux.oracle.com/cve/CVE-2010-3770.html" source="CVE"/>
        <reference ref_id="CVE-2010-3771" ref_url="http://linux.oracle.com/cve/CVE-2010-3771.html" source="CVE"/>
        <reference ref_id="CVE-2010-3772" ref_url="http://linux.oracle.com/cve/CVE-2010-3772.html" source="CVE"/>
        <reference ref_id="CVE-2010-3773" ref_url="http://linux.oracle.com/cve/CVE-2010-3773.html" source="CVE"/>
        <reference ref_id="CVE-2010-3774" ref_url="http://linux.oracle.com/cve/CVE-2010-3774.html" source="CVE"/>
        <reference ref_id="CVE-2010-3775" ref_url="http://linux.oracle.com/cve/CVE-2010-3775.html" source="CVE"/>
        <reference ref_id="CVE-2010-3776" ref_url="http://linux.oracle.com/cve/CVE-2010-3776.html" source="CVE"/>
        <reference ref_id="CVE-2010-3777" ref_url="http://linux.oracle.com/cve/CVE-2010-3777.html" source="CVE"/>
        <description>Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:28.747-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.988-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:06.803-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23532 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.607-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:39.627-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:108195"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:108099"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el5" test_ref="oval:org.mitre.oval:tst:108302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:107612"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:108056"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el6_0" test_ref="oval:org.mitre.oval:tst:108065"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23530" version="41" class="patch">
      <metadata>
        <title>ELSA-2011:1423: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2011:1423-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1423.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0708" ref_url="http://linux.oracle.com/cve/CVE-2011-0708.html" source="CVE"/>
        <reference ref_id="CVE-2011-1148" ref_url="http://linux.oracle.com/cve/CVE-2011-1148.html" source="CVE"/>
        <reference ref_id="CVE-2011-1466" ref_url="http://linux.oracle.com/cve/CVE-2011-1466.html" source="CVE"/>
        <reference ref_id="CVE-2011-1468" ref_url="http://linux.oracle.com/cve/CVE-2011-1468.html" source="CVE"/>
        <reference ref_id="CVE-2011-1469" ref_url="http://linux.oracle.com/cve/CVE-2011-1469.html" source="CVE"/>
        <reference ref_id="CVE-2011-1471" ref_url="http://linux.oracle.com/cve/CVE-2011-1471.html" source="CVE"/>
        <reference ref_id="CVE-2011-1938" ref_url="http://linux.oracle.com/cve/CVE-2011-1938.html" source="CVE"/>
        <reference ref_id="CVE-2011-2202" ref_url="http://linux.oracle.com/cve/CVE-2011-2202.html" source="CVE"/>
        <reference ref_id="CVE-2011-2483" ref_url="http://linux.oracle.com/cve/CVE-2011-2483.html" source="CVE"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:15.896-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.477-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:06.253-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23530 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:47.170-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:39.219-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109372"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109480"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109398"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109030"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109302"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109482"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109540"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109494"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108569"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109148"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108799"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108572"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109443"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109484"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109513"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109451"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109425"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109226"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109023"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108540"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109229"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109420"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109530"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109381"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109483"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:108893"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:108983"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109510"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109390"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109049"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109490"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109091"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109322"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109472"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109167"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109344"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109315"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109238"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:108961"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109206"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109346"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109402"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109341"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109081"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109489"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109252"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109176"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23527" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1480: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1480-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1480.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a CANVAS element, a mozTextStyle attribute, and an onresize event.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:33.304-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.143-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.880-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23527 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.593-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.839-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:48:12.777-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:48:12.777-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107788"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23525" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0898: mesa security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mesa</product>
        </affected>
        <reference ref_id="ELSA-2013:0898-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0898.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1993" ref_url="http://linux.oracle.com/cve/CVE-2013-1993.html" source="CVE"/>
        <description>Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:45.270-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.968-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.617-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23525 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:43.553-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mesa-libGLw is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107231"/>
          <criterion comment="glx-utils is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107287"/>
          <criterion comment="mesa-libGLU is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:106890"/>
          <criterion comment="mesa-libGL-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107521"/>
          <criterion comment="mesa-libGLU-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107423"/>
          <criterion comment="mesa-source is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107092"/>
          <criterion comment="mesa-libGLw-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107364"/>
          <criterion comment="mesa-libOSMesa is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107550"/>
          <criterion comment="mesa-libGL is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107573"/>
          <criterion comment="mesa-libOSMesa-devel is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:107501"/>
          <criterion comment="mesa is earlier than 0:6.5.1-7.11.el5_9" test_ref="oval:org.mitre.oval:tst:106577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23524" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0807: hypervkvpd security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>hypervkvpd</product>
        </affected>
        <reference ref_id="ELSA-2013:0807-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0807.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5532" ref_url="http://linux.oracle.com/cve/CVE-2012-5532.html" source="CVE"/>
        <description>The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message.	NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:51.123-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.908-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.519-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23524 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:43.987-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="hypervkvpd is earlier than 0:0-0.7.el5_9.3" test_ref="oval:org.mitre.oval:tst:107330"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23522" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0847: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0847-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0847.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0153" ref_url="http://linux.oracle.com/cve/CVE-2013-0153.html" source="CVE"/>
        <description>The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:48.180-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.709-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.130-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23522 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.158-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.169-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107405"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107114"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107519"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107243"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107398"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107533"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107465"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107251"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:106732"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107181"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107447"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.6.1.el5" test_ref="oval:org.mitre.oval:tst:107515"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23516" version="15" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0310: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0310-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0310.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by triggering incorrect use of the TypedArrayObject class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:37.067-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:05:03.669-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:06.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23516 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:31.307-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:47:41.238-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:47:41.238-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113348"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113511"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23512" version="97" class="patch">
      <metadata>
        <title>ELSA-2011:0301: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2011:0301-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0301.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0562" ref_url="http://linux.oracle.com/cve/CVE-2011-0562.html" source="CVE"/>
        <reference ref_id="CVE-2011-0563" ref_url="http://linux.oracle.com/cve/CVE-2011-0563.html" source="CVE"/>
        <reference ref_id="CVE-2011-0565" ref_url="http://linux.oracle.com/cve/CVE-2011-0565.html" source="CVE"/>
        <reference ref_id="CVE-2011-0566" ref_url="http://linux.oracle.com/cve/CVE-2011-0566.html" source="CVE"/>
        <reference ref_id="CVE-2011-0567" ref_url="http://linux.oracle.com/cve/CVE-2011-0567.html" source="CVE"/>
        <reference ref_id="CVE-2011-0585" ref_url="http://linux.oracle.com/cve/CVE-2011-0585.html" source="CVE"/>
        <reference ref_id="CVE-2011-0586" ref_url="http://linux.oracle.com/cve/CVE-2011-0586.html" source="CVE"/>
        <reference ref_id="CVE-2011-0587" ref_url="http://linux.oracle.com/cve/CVE-2011-0587.html" source="CVE"/>
        <reference ref_id="CVE-2011-0589" ref_url="http://linux.oracle.com/cve/CVE-2011-0589.html" source="CVE"/>
        <reference ref_id="CVE-2011-0590" ref_url="http://linux.oracle.com/cve/CVE-2011-0590.html" source="CVE"/>
        <reference ref_id="CVE-2011-0591" ref_url="http://linux.oracle.com/cve/CVE-2011-0591.html" source="CVE"/>
        <reference ref_id="CVE-2011-0592" ref_url="http://linux.oracle.com/cve/CVE-2011-0592.html" source="CVE"/>
        <reference ref_id="CVE-2011-0593" ref_url="http://linux.oracle.com/cve/CVE-2011-0593.html" source="CVE"/>
        <reference ref_id="CVE-2011-0594" ref_url="http://linux.oracle.com/cve/CVE-2011-0594.html" source="CVE"/>
        <reference ref_id="CVE-2011-0595" ref_url="http://linux.oracle.com/cve/CVE-2011-0595.html" source="CVE"/>
        <reference ref_id="CVE-2011-0596" ref_url="http://linux.oracle.com/cve/CVE-2011-0596.html" source="CVE"/>
        <reference ref_id="CVE-2011-0598" ref_url="http://linux.oracle.com/cve/CVE-2011-0598.html" source="CVE"/>
        <reference ref_id="CVE-2011-0599" ref_url="http://linux.oracle.com/cve/CVE-2011-0599.html" source="CVE"/>
        <reference ref_id="CVE-2011-0600" ref_url="http://linux.oracle.com/cve/CVE-2011-0600.html" source="CVE"/>
        <reference ref_id="CVE-2011-0602" ref_url="http://linux.oracle.com/cve/CVE-2011-0602.html" source="CVE"/>
        <reference ref_id="CVE-2011-0603" ref_url="http://linux.oracle.com/cve/CVE-2011-0603.html" source="CVE"/>
        <reference ref_id="CVE-2011-0604" ref_url="http://linux.oracle.com/cve/CVE-2011-0604.html" source="CVE"/>
        <reference ref_id="CVE-2011-0606" ref_url="http://linux.oracle.com/cve/CVE-2011-0606.html" source="CVE"/>
        <description>Stack-based buffer overflow in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to a crafted length value, a different vulnerability than CVE-2011-0563 and CVE-2011-0589.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:41.443-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:17.580-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:02.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23512 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.974-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:36.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:108729"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:108703"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:108667"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:108421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23511" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0894: systemtap security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2010:0894-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0894.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4170" ref_url="http://linux.oracle.com/cve/CVE-2010-4170.html" source="CVE"/>
        <reference ref_id="CVE-2010-4171" ref_url="http://linux.oracle.com/cve/CVE-2010-4171.html" source="CVE"/>
        <description>The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary kernel modules).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:36.368-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:17.470-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:02.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23511 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.834-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:36.375-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-client is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108173"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108312"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:107817"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108176"/>
            <criterion comment="systemtap is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108205"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108266"/>
            <criterion comment="systemtap-server is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108025"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-runtime is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107915"/>
            <criterion comment="systemtap-client is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107944"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107878"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108255"/>
            <criterion comment="systemtap is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108144"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108098"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108282"/>
            <criterion comment="systemtap-server is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107874"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23506" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1475: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2013:1475-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1475.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0255" ref_url="http://linux.oracle.com/cve/CVE-2013-0255.html" source="CVE"/>
        <reference ref_id="CVE-2013-1000" ref_url="http://linux.oracle.com/cve/CVE-2013-1000.html" source="CVE"/>
        <description>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:23.432-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.440-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:00.352-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23506 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:41.771-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:35.044-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:47:10.276-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:47:10.276-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107559"/>
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107665"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107735"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107813"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107618"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107582"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107149"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107384"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107528"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107659"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107408"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107680"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107832"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107593"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107492"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107679"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107557"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107828"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:106856"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107764"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107747"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107426"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23504" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:0079: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0079-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0079.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3659" ref_url="http://linux.oracle.com/cve/CVE-2011-3659.html" source="CVE"/>
        <reference ref_id="CVE-2011-3670" ref_url="http://linux.oracle.com/cve/CVE-2011-3670.html" source="CVE"/>
        <reference ref_id="CVE-2012-0442" ref_url="http://linux.oracle.com/cve/CVE-2012-0442.html" source="CVE"/>
        <reference ref_id="CVE-2012-0444" ref_url="http://linux.oracle.com/cve/CVE-2012-0444.html" source="CVE"/>
        <reference ref_id="CVE-2012-0449" ref_url="http://linux.oracle.com/cve/CVE-2012-0449.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:17.195-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.166-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:59.990-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23504 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.321-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:34.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:109403"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:109729"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:109565"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:109807"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:109364"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:109464"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23501" version="13" class="patch">
      <metadata>
        <title>ELSA-2014:0163: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2014:0163-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0163.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6367" ref_url="http://linux.oracle.com/cve/CVE-2013-6367.html" source="CVE"/>
        <reference ref_id="CVE-2013-6368" ref_url="http://linux.oracle.com/cve/CVE-2013-6368.html" source="CVE"/>
        <description>The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:09.067-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.875-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:59.597-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23501 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.970-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:34.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kmod-kvm-debug is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:107856"/>
          <criterion comment="kvm-tools is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:107274"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:107708"/>
          <criterion comment="kvm is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:108079"/>
          <criterion comment="kmod-kvm is earlier than 0:83-266.el5_10.1" test_ref="oval:org.mitre.oval:tst:107246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23500" version="25" class="patch">
      <metadata>
        <title>ELSA-2011:1341: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1341-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1341.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2372" ref_url="http://linux.oracle.com/cve/CVE-2011-2372.html" source="CVE"/>
        <reference ref_id="CVE-2011-2995" ref_url="http://linux.oracle.com/cve/CVE-2011-2995.html" source="CVE"/>
        <reference ref_id="CVE-2011-2998" ref_url="http://linux.oracle.com/cve/CVE-2011-2998.html" source="CVE"/>
        <reference ref_id="CVE-2011-2999" ref_url="http://linux.oracle.com/cve/CVE-2011-2999.html" source="CVE"/>
        <reference ref_id="CVE-2011-3000" ref_url="http://linux.oracle.com/cve/CVE-2011-3000.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:04.330-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.733-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:59.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23500 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.782-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:34.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:108948"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:109310"/>
            <criterion comment="firefox is earlier than 0:3.6.23-2.el5_7" test_ref="oval:org.mitre.oval:tst:109124"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:3.6.23-2.el6_1" test_ref="oval:org.mitre.oval:tst:109393"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109412"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109417"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23498" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0771: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0771-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0771.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1944" ref_url="http://linux.oracle.com/cve/CVE-2013-1944.html" source="CVE"/>
        <description>The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:40.996-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.549-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:58.986-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23498 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.780-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:33.799-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:45:26.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:45:26.232-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:107208"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:107365"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:107420"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:107076"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:107057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23495" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1422: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2011:1422-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1422.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4073" ref_url="http://linux.oracle.com/cve/CVE-2011-4073.html" source="CVE"/>
        <description>Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:13.821-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.412-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:58.780-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23495 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.215-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:33.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:109260"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:109467"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:109326"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:109473"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23493" version="86" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0770: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0770-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0770.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1488" ref_url="http://linux.oracle.com/cve/CVE-2013-1488.html" source="CVE"/>
        <reference ref_id="CVE-2013-1518" ref_url="http://linux.oracle.com/cve/CVE-2013-1518.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2415" ref_url="http://linux.oracle.com/cve/CVE-2013-2415.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2421" ref_url="http://linux.oracle.com/cve/CVE-2013-2421.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2426" ref_url="http://linux.oracle.com/cve/CVE-2013-2426.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2431" ref_url="http://linux.oracle.com/cve/CVE-2013-2431.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to bypassing the Java sandbox using "method handle intrinsic frames."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:42.574-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.843-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23493 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.499-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.844-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:44:43.046-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:44:43.046-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:106958"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:107424"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:107457"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:107410"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:106957"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107006"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107154"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107433"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107189"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107013"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23491" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0640: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference ref_id="ELSA-2013:0640-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0640.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3546" ref_url="http://linux.oracle.com/cve/CVE-2012-3546.html" source="CVE"/>
        <reference ref_id="CVE-2012-5885" ref_url="http://linux.oracle.com/cve/CVE-2012-5885.html" source="CVE"/>
        <reference ref_id="CVE-2012-5886" ref_url="http://linux.oracle.com/cve/CVE-2012-5886.html" source="CVE"/>
        <reference ref_id="CVE-2012-5887" ref_url="http://linux.oracle.com/cve/CVE-2012-5887.html" source="CVE"/>
        <description>The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:52.294-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.614-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.414-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23491 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:47.477-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107285"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:106335"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:106381"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107143"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107282"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107033"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107209"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107367"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107062"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:106339"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.38.el5_9" test_ref="oval:org.mitre.oval:tst:107212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23489" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0587: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2013:0587-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0587.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4929" ref_url="http://linux.oracle.com/cve/CVE-2012-4929.html" source="CVE"/>
        <reference ref_id="CVE-2013-0166" ref_url="http://linux.oracle.com/cve/CVE-2013-0166.html" source="CVE"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <description>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:01.790-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.437-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.131-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23489 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:41.330-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.297-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:43:47.262-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:43:47.262-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:106258"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:107214"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:106990"/>
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:107182"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:107117"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:106825"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:107131"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23488" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0124: net-snmp security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>net-snmp</product>
        </affected>
        <reference ref_id="ELSA-2013:0124-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0124.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2141" ref_url="http://linux.oracle.com/cve/CVE-2012-2141.html" source="CVE"/>
        <description>Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:59.356-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.358-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.024-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23488 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.996-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.196-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="net-snmp-utils is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:106109"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:107084"/>
          <criterion comment="net-snmp-perl is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:106761"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:107070"/>
          <criterion comment="net-snmp is earlier than 1:5.3.2.2-20.el5" test_ref="oval:org.mitre.oval:tst:106923"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23487" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0883: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2013:0883-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0883.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2116" ref_url="http://linux.oracle.com/cve/CVE-2013-2116.html" source="CVE"/>
        <description>The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length.  NOTE: this might be due to an incorrect fix for CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:36.116-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.263-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.879-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23487 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.402-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.091-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107534"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107569"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107352"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107494"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:107425"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:107400"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:107318"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23486" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0123: OpenIPMI security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>OpenIPMI</product>
        </affected>
        <reference ref_id="ELSA-2013:0123-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0123.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4339" ref_url="http://linux.oracle.com/cve/CVE-2011-4339.html" source="CVE"/>
        <description>ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:05.413-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.768-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23486 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.685-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:31.979-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="OpenIPMI-libs is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:106821"/>
          <criterion comment="OpenIPMI-python is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:106833"/>
          <criterion comment="OpenIPMI-tools is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:106839"/>
          <criterion comment="OpenIPMI-gui is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:107034"/>
          <criterion comment="OpenIPMI-perl is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:106765"/>
          <criterion comment="OpenIPMI is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:107073"/>
          <criterion comment="OpenIPMI-devel is earlier than 0:2.0.16-16.el5" test_ref="oval:org.mitre.oval:tst:107097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23483" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0983: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0983-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0983.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2174" ref_url="http://linux.oracle.com/cve/CVE-2013-2174.html" source="CVE"/>
        <description>Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:45.778-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.847-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23483 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.482-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:31.539-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:42:58.917-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:42:58.917-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:107253"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:106843"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:107585"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:107567"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:107370"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23482" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1806: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2013:1806-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1806.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4408" ref_url="http://linux.oracle.com/cve/CVE-2013-4408.html" source="CVE"/>
        <reference ref_id="CVE-2013-4475" ref_url="http://linux.oracle.com/cve/CVE-2013-4475.html" source="CVE"/>
        <description>Samba 3.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:28.531-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.714-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.100-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23482 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.629-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:31.344-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:42:18.229-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:42:18.229-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107549"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107922"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107138"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107821"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107951"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107766"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107965"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107694"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107894"/>
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107908"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107357"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107625"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107696"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107911"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107875"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107900"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107949"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107880"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107768"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107536"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23481" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0982: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0982-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0982.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1682" ref_url="http://linux.oracle.com/cve/CVE-2013-1682.html" source="CVE"/>
        <reference ref_id="CVE-2013-1684" ref_url="http://linux.oracle.com/cve/CVE-2013-1684.html" source="CVE"/>
        <reference ref_id="CVE-2013-1685" ref_url="http://linux.oracle.com/cve/CVE-2013-1685.html" source="CVE"/>
        <reference ref_id="CVE-2013-1686" ref_url="http://linux.oracle.com/cve/CVE-2013-1686.html" source="CVE"/>
        <reference ref_id="CVE-2013-1687" ref_url="http://linux.oracle.com/cve/CVE-2013-1687.html" source="CVE"/>
        <reference ref_id="CVE-2013-1690" ref_url="http://linux.oracle.com/cve/CVE-2013-1690.html" source="CVE"/>
        <reference ref_id="CVE-2013-1692" ref_url="http://linux.oracle.com/cve/CVE-2013-1692.html" source="CVE"/>
        <reference ref_id="CVE-2013-1693" ref_url="http://linux.oracle.com/cve/CVE-2013-1693.html" source="CVE"/>
        <reference ref_id="CVE-2013-1694" ref_url="http://linux.oracle.com/cve/CVE-2013-1694.html" source="CVE"/>
        <reference ref_id="CVE-2013-1697" ref_url="http://linux.oracle.com/cve/CVE-2013-1697.html" source="CVE"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:57.160-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.469-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:55.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23481 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.108-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:30.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:107205"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107471"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23480" version="61" class="patch">
      <metadata>
        <title>ELSA-2014:0027: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0027-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0027.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5893" ref_url="http://linux.oracle.com/cve/CVE-2013-5893.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:09.319-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.106-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:55.052-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23480 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.660-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:30.451-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:108037"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:107858"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:107886"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:107947"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.51-2.4.4.1.el5_10" test_ref="oval:org.mitre.oval:tst:108044"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23478" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0942: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2013:0942-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0942.html" source="VENDOR"/>
        <reference ref_id="CVE-2002-2443" ref_url="http://linux.oracle.com/cve/CVE-2002-2443.html" source="CVE"/>
        <description>schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:38.302-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:12.822-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:54.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23478 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.597-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:30.317-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:40:42.798-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:40:42.798-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107312"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107496"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:106642"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107487"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107572"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:106921"/>
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107311"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107102"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107156"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107548"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107293"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107421"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107356"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23476" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1245: httpd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2011:1245-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1245.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3192" ref_url="http://linux.oracle.com/cve/CVE-2011-3192.html" source="CVE"/>
        <description>The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:22.515-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:12.725-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:54.491-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23476 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.984-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:30.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:109151"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:109143"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:108420"/>
            <criterion comment="httpd is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:108892"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109187"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109175"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109058"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:108991"/>
            <criterion comment="httpd is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23475" version="85" class="patch">
      <metadata>
        <title>ELSA-2012:1351: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1351-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1351.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1956" ref_url="http://linux.oracle.com/cve/CVE-2012-1956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3982" ref_url="http://linux.oracle.com/cve/CVE-2012-3982.html" source="CVE"/>
        <reference ref_id="CVE-2012-3986" ref_url="http://linux.oracle.com/cve/CVE-2012-3986.html" source="CVE"/>
        <reference ref_id="CVE-2012-3988" ref_url="http://linux.oracle.com/cve/CVE-2012-3988.html" source="CVE"/>
        <reference ref_id="CVE-2012-3990" ref_url="http://linux.oracle.com/cve/CVE-2012-3990.html" source="CVE"/>
        <reference ref_id="CVE-2012-3991" ref_url="http://linux.oracle.com/cve/CVE-2012-3991.html" source="CVE"/>
        <reference ref_id="CVE-2012-3992" ref_url="http://linux.oracle.com/cve/CVE-2012-3992.html" source="CVE"/>
        <reference ref_id="CVE-2012-3993" ref_url="http://linux.oracle.com/cve/CVE-2012-3993.html" source="CVE"/>
        <reference ref_id="CVE-2012-3994" ref_url="http://linux.oracle.com/cve/CVE-2012-3994.html" source="CVE"/>
        <reference ref_id="CVE-2012-3995" ref_url="http://linux.oracle.com/cve/CVE-2012-3995.html" source="CVE"/>
        <reference ref_id="CVE-2012-4179" ref_url="http://linux.oracle.com/cve/CVE-2012-4179.html" source="CVE"/>
        <reference ref_id="CVE-2012-4180" ref_url="http://linux.oracle.com/cve/CVE-2012-4180.html" source="CVE"/>
        <reference ref_id="CVE-2012-4181" ref_url="http://linux.oracle.com/cve/CVE-2012-4181.html" source="CVE"/>
        <reference ref_id="CVE-2012-4182" ref_url="http://linux.oracle.com/cve/CVE-2012-4182.html" source="CVE"/>
        <reference ref_id="CVE-2012-4183" ref_url="http://linux.oracle.com/cve/CVE-2012-4183.html" source="CVE"/>
        <reference ref_id="CVE-2012-4184" ref_url="http://linux.oracle.com/cve/CVE-2012-4184.html" source="CVE"/>
        <reference ref_id="CVE-2012-4185" ref_url="http://linux.oracle.com/cve/CVE-2012-4185.html" source="CVE"/>
        <reference ref_id="CVE-2012-4186" ref_url="http://linux.oracle.com/cve/CVE-2012-4186.html" source="CVE"/>
        <reference ref_id="CVE-2012-4187" ref_url="http://linux.oracle.com/cve/CVE-2012-4187.html" source="CVE"/>
        <reference ref_id="CVE-2012-4188" ref_url="http://linux.oracle.com/cve/CVE-2012-4188.html" source="CVE"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:08.037-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:12.314-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:53.673-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23475 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.743-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:29.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:111235"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:111199"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23474" version="70" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1482: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1482-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1482.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4201" ref_url="http://linux.oracle.com/cve/CVE-2012-4201.html" source="CVE"/>
        <reference ref_id="CVE-2012-4202" ref_url="http://linux.oracle.com/cve/CVE-2012-4202.html" source="CVE"/>
        <reference ref_id="CVE-2012-4207" ref_url="http://linux.oracle.com/cve/CVE-2012-4207.html" source="CVE"/>
        <reference ref_id="CVE-2012-4209" ref_url="http://linux.oracle.com/cve/CVE-2012-4209.html" source="CVE"/>
        <reference ref_id="CVE-2012-4210" ref_url="http://linux.oracle.com/cve/CVE-2012-4210.html" source="CVE"/>
        <reference ref_id="CVE-2012-4214" ref_url="http://linux.oracle.com/cve/CVE-2012-4214.html" source="CVE"/>
        <reference ref_id="CVE-2012-4215" ref_url="http://linux.oracle.com/cve/CVE-2012-4215.html" source="CVE"/>
        <reference ref_id="CVE-2012-4216" ref_url="http://linux.oracle.com/cve/CVE-2012-4216.html" source="CVE"/>
        <reference ref_id="CVE-2012-5829" ref_url="http://linux.oracle.com/cve/CVE-2012-5829.html" source="CVE"/>
        <reference ref_id="CVE-2012-5830" ref_url="http://linux.oracle.com/cve/CVE-2012-5830.html" source="CVE"/>
        <reference ref_id="CVE-2012-5833" ref_url="http://linux.oracle.com/cve/CVE-2012-5833.html" source="CVE"/>
        <reference ref_id="CVE-2012-5835" ref_url="http://linux.oracle.com/cve/CVE-2012-5835.html" source="CVE"/>
        <reference ref_id="CVE-2012-5839" ref_url="http://linux.oracle.com/cve/CVE-2012-5839.html" source="CVE"/>
        <reference ref_id="CVE-2012-5840" ref_url="http://linux.oracle.com/cve/CVE-2012-5840.html" source="CVE"/>
        <reference ref_id="CVE-2012-5841" ref_url="http://linux.oracle.com/cve/CVE-2012-5841.html" source="CVE"/>
        <reference ref_id="CVE-2012-5842" ref_url="http://linux.oracle.com/cve/CVE-2012-5842.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:39.445-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.941-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23474 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.222-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:29.179-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:39:34.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:39:34.264-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106943"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106846"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106944"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:106628"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:106742"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:107022"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23470" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1459: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference ref_id="ELSA-2013:1459-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1459.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6085" ref_url="http://linux.oracle.com/cve/CVE-2012-6085.html" source="CVE"/>
        <reference ref_id="CVE-2013-4351" ref_url="http://linux.oracle.com/cve/CVE-2013-4351.html" source="CVE"/>
        <reference ref_id="CVE-2013-4402" ref_url="http://linux.oracle.com/cve/CVE-2013-4402.html" source="CVE"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:34.507-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.628-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.443-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23470 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.872-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.738-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:38:50.654-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:38:50.654-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:107207"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:106836"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:106842"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23467" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0568: dbus-glib security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus-glib</product>
        </affected>
        <reference ref_id="ELSA-2013:0568-03" ref_url="http://linux.oracle.com/errata/ELSA-2013-0568.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0292" ref_url="http://linux.oracle.com/cve/CVE-2013-0292.html" source="CVE"/>
        <description>The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:56.606-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.410-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23467 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.359-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.507-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:38:15.846-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:38:15.846-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:106987"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:106995"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:106772"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:107082"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23465" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0815: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:0815-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0815.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3499" ref_url="http://linux.oracle.com/cve/CVE-2012-3499.html" source="CVE"/>
        <reference ref_id="CVE-2012-4558" ref_url="http://linux.oracle.com/cve/CVE-2012-4558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1862" ref_url="http://linux.oracle.com/cve/CVE-2013-1862.html" source="CVE"/>
        <description>mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:48.693-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.180-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:51.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23465 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:34.157-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.231-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:37:37.370-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:37:37.370-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107162"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107327"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107298"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107488"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107390"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107191"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107478"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107238"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107348"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23464" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1411: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2013:1411-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1411.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4336" ref_url="http://linux.oracle.com/cve/CVE-2013-4336.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:41.069-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.107-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:51.700-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23464 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.911-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.135-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nscd is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:107395"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:107733"/>
          <criterion comment="glibc-common is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:107332"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:107730"/>
          <criterion comment="glibc is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:107619"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-118.el5_10.2" test_ref="oval:org.mitre.oval:tst:107596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23463" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0126: squirrelmail security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference ref_id="ELSA-2013:0126-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0126.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2124" ref_url="http://linux.oracle.com/cve/CVE-2012-2124.html" source="CVE"/>
        <description>functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files.  NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:59.042-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.042-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:51.607-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23463 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.960-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.050-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="squirrelmail is earlier than 0:1.4.8-21.el5" test_ref="oval:org.mitre.oval:tst:106997"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23462" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0271: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
          <product>libproxy</product>
        </affected>
        <reference ref_id="ELSA-2013:0271-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0271.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0775" ref_url="http://linux.oracle.com/cve/CVE-2013-0775.html" source="CVE"/>
        <reference ref_id="CVE-2013-0776" ref_url="http://linux.oracle.com/cve/CVE-2013-0776.html" source="CVE"/>
        <reference ref_id="CVE-2013-0780" ref_url="http://linux.oracle.com/cve/CVE-2013-0780.html" source="CVE"/>
        <reference ref_id="CVE-2013-0782" ref_url="http://linux.oracle.com/cve/CVE-2013-0782.html" source="CVE"/>
        <reference ref_id="CVE-2013-0783" ref_url="http://linux.oracle.com/cve/CVE-2013-0783.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:27.894-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.839-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:51.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23462 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.442-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:27.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="yelp is earlier than 0:2.28.1-17.el6_3" test_ref="oval:org.mitre.oval:tst:111026"/>
            <criterion comment="libproxy-bin is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111368"/>
            <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111442"/>
            <criterion comment="libproxy-devel is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111437"/>
            <criterion comment="libproxy-webkit is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111307"/>
            <criterion comment="libproxy is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111462"/>
            <criterion comment="libproxy-gnome is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111353"/>
            <criterion comment="libproxy-python is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111506"/>
            <criterion comment="libproxy-kde is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111299"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111385"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111515"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111045"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111045"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="yelp is earlier than 0:2.16.0-30.el5_9" test_ref="oval:org.mitre.oval:tst:111189"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:111461"/>
            <criterion comment="devhelp is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:111469"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111213"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111160"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111286"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23456" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0168: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0168-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0168.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1568" ref_url="http://linux.oracle.com/cve/CVE-2012-1568.html" source="CVE"/>
        <reference ref_id="CVE-2012-4444" ref_url="http://linux.oracle.com/cve/CVE-2012-4444.html" source="CVE"/>
        <reference ref_id="CVE-2012-5515" ref_url="http://linux.oracle.com/cve/CVE-2012-5515.html" source="CVE"/>
        <description>The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:59.762-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.183-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:50.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23456 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:34.285-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:27.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:106829"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:107020"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:107096"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:107016"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:107035"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:106894"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:107065"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:106911"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:106907"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:107069"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:107031"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.1.1.el5" test_ref="oval:org.mitre.oval:tst:106353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23455" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0165: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0165-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0165.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3174" ref_url="http://linux.oracle.com/cve/CVE-2012-3174.html" source="CVE"/>
        <reference ref_id="CVE-2013-0422" ref_url="http://linux.oracle.com/cve/CVE-2013-0422.html" source="CVE"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:58.148-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.076-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:50.254-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23455 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.164-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:26.946-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:36:41.160-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:36:41.160-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106133"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106901"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106837"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106874"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:107132"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:107113"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:107081"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:106714"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:106975"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:106820"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23453" version="97" class="patch">
      <metadata>
        <title>ELSA-2010:0987: java-1.6.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0987-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0987.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-1321" ref_url="http://linux.oracle.com/cve/CVE-2010-1321.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3550" ref_url="http://linux.oracle.com/cve/CVE-2010-3550.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3555" ref_url="http://linux.oracle.com/cve/CVE-2010-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-3556" ref_url="http://linux.oracle.com/cve/CVE-2010-3556.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3558" ref_url="http://linux.oracle.com/cve/CVE-2010-3558.html" source="CVE"/>
        <reference ref_id="CVE-2010-3560" ref_url="http://linux.oracle.com/cve/CVE-2010-3560.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3563" ref_url="http://linux.oracle.com/cve/CVE-2010-3563.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3566" ref_url="http://linux.oracle.com/cve/CVE-2010-3566.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <reference ref_id="CVE-2010-3572" ref_url="http://linux.oracle.com/cve/CVE-2010-3572.html" source="CVE"/>
        <reference ref_id="CVE-2010-3573" ref_url="http://linux.oracle.com/cve/CVE-2010-3573.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:38.892-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.501-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:49.334-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23453 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.964-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:26.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107995"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107481"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:108007"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107919"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107928"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107837"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:108148"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:108209"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:108206"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:108253"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107963"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107913"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107577"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107909"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107818"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23452" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0132: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0132-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0132.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:08.781-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.325-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:49.052-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23452 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.601-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:26.111-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:35:44.520-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:35:44.520-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:107996"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:107462"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23451" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:1458: gnupg security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnupg</product>
        </affected>
        <reference ref_id="ELSA-2013:1458-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1458.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6085" ref_url="http://linux.oracle.com/cve/CVE-2012-6085.html" source="CVE"/>
        <reference ref_id="CVE-2013-4242" ref_url="http://linux.oracle.com/cve/CVE-2013-4242.html" source="CVE"/>
        <reference ref_id="CVE-2013-4351" ref_url="http://linux.oracle.com/cve/CVE-2013-4351.html" source="CVE"/>
        <reference ref_id="CVE-2013-4402" ref_url="http://linux.oracle.com/cve/CVE-2013-4402.html" source="CVE"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:41.795-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.219-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.890-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23451 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.295-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="gnupg is earlier than 0:1.4.5-18.el5_10" test_ref="oval:org.mitre.oval:tst:107689"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23450" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1267: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1267-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1267.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
The RHSA-2011:1243 Thunderbird update rendered HTTPS certificates signed by
a certain Certificate Authority (CA) as untrusted, but made an exception
for a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)
All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:18.754-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.829-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23450 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.802-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-25.el5" test_ref="oval:org.mitre.oval:tst:109275"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.14-1.el6_1" test_ref="oval:org.mitre.oval:tst:109185"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23449" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0581: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2013:0581-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0581.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0338" ref_url="http://linux.oracle.com/cve/CVE-2013-0338.html" source="CVE"/>
        <description>libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:05.824-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.090-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.659-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23449 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.717-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:106789"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:106852"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:107174"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:106236"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:106862"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:107226"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:107203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23448" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0169: java-1.5.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0169-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0169.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <description>Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the color profile parser that allows remote attackers to execute arbitrary code via a crafted Tag structure in a color profile.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:24.957-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.934-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.455-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23448 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.749-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108333"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108315"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:107451"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108119"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108196"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108353"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:107654"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:107575"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108296"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108258"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108385"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108438"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108347"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108348"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23446" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0883: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2013:0883-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0883.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2116" ref_url="http://linux.oracle.com/cve/CVE-2013-2116.html" source="CVE"/>
        <description>The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length.  NOTE: this might be due to an incorrect fix for CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:38.199-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.861-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23446 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.139-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.437-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:35:12.547-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:35:12.547-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:112092"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:112106"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111406"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:111537"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:111145"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:111639"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23445" version="5" class="patch">
      <metadata>
        <title>ELSA-2013:0214: nss and nspr security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nss</product>
          <product>nspr</product>
        </affected>
        <reference ref_id="ELSA-2013:0214-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0214.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.
It was found that a Certificate Authority (CA) mis-issued two intermediate
certificates to customers. These certificates could be used to launch
man-in-the-middle attacks. This update renders those certificates as
untrusted. This covers all uses of the certificates, including SSL, S/MIME,
and code signing. (BZ#890605)
In addition, the nss package has been upgraded to upstream version 3.13.6,
and the nspr package has been upgraded to upstream version 4.9.2. These
updates provide a number of bug fixes and enhancements over the previous
versions. (BZ#893371, BZ#893372)
All NSS and NSPR users should upgrade to these updated packages, which
correct these issues and add these enhancements. After installing the
update, applications using NSS and NSPR must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:59.539-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.813-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23445 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.599-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.354-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr-devel is earlier than 0:4.9.2-2.el5_9" test_ref="oval:org.mitre.oval:tst:106780"/>
          <criterion comment="nspr is earlier than 0:4.9.2-2.el5_9" test_ref="oval:org.mitre.oval:tst:107023"/>
          <criterion comment="nss is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:106893"/>
          <criterion comment="nss-devel is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:106635"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:106959"/>
          <criterion comment="nss-tools is earlier than 0:3.13.6-3.el5_9" test_ref="oval:org.mitre.oval:tst:107111"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23444" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1457: libgcrypt security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference ref_id="ELSA-2013:1457-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1457.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4242" ref_url="http://linux.oracle.com/cve/CVE-2013-4242.html" source="CVE"/>
        <description>GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:33.974-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.741-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.144-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23444 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:28.685-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.251-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:34:23.298-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:34:23.298-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:107763"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:107602"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:107403"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:107646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23439" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1512: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:1512-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1512.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5134" ref_url="http://linux.oracle.com/cve/CVE-2012-5134.html" source="CVE"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:44.018-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.364-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:47.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23439 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.552-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:24.787-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:33:45.085-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:33:45.085-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:107021"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:106930"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:106793"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106915"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106880"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106227"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23438" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1508: cyrus-imapd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference ref_id="ELSA-2011:1508-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1508.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3372" ref_url="http://linux.oracle.com/cve/CVE-2011-3372.html" source="CVE"/>
        <reference ref_id="CVE-2011-3481" ref_url="http://linux.oracle.com/cve/CVE-2011-3481.html" source="CVE"/>
        <description>The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:05.508-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.270-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:47.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23438 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.432-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:24.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:108804"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:109228"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:109631"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:108887"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:109633"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:109471"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:109462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23436" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0604: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0604-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0604.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:52.706-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.839-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:46.574-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23436 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:28.861-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:24.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:107178"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:107215"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:106665"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:107194"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.36.1.11.9.el5_9" test_ref="oval:org.mitre.oval:tst:107305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23435" version="33" class="patch">
      <metadata>
        <title>ELSA-2013:0747: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0747-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0747.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6537" ref_url="http://linux.oracle.com/cve/CVE-2012-6537.html" source="CVE"/>
        <reference ref_id="CVE-2012-6542" ref_url="http://linux.oracle.com/cve/CVE-2012-6542.html" source="CVE"/>
        <reference ref_id="CVE-2012-6546" ref_url="http://linux.oracle.com/cve/CVE-2012-6546.html" source="CVE"/>
        <reference ref_id="CVE-2012-6547" ref_url="http://linux.oracle.com/cve/CVE-2012-6547.html" source="CVE"/>
        <reference ref_id="CVE-2013-0216" ref_url="http://linux.oracle.com/cve/CVE-2013-0216.html" source="CVE"/>
        <reference ref_id="CVE-2013-0231" ref_url="http://linux.oracle.com/cve/CVE-2013-0231.html" source="CVE"/>
        <reference ref_id="CVE-2013-1826" ref_url="http://linux.oracle.com/cve/CVE-2013-1826.html" source="CVE"/>
        <description>The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:37.223-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.621-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:46.223-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23435 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:28.985-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:23.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107301"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107409"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107480"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107394"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107233"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107284"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107435"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107281"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107450"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107449"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107041"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.4.1.el5" test_ref="oval:org.mitre.oval:tst:107310"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23434" version="38" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1476: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1476-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1476.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5590" ref_url="http://linux.oracle.com/cve/CVE-2013-5590.html" source="CVE"/>
        <reference ref_id="CVE-2013-5595" ref_url="http://linux.oracle.com/cve/CVE-2013-5595.html" source="CVE"/>
        <reference ref_id="CVE-2013-5597" ref_url="http://linux.oracle.com/cve/CVE-2013-5597.html" source="CVE"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <reference ref_id="CVE-2013-5600" ref_url="http://linux.oracle.com/cve/CVE-2013-5600.html" source="CVE"/>
        <reference ref_id="CVE-2013-5601" ref_url="http://linux.oracle.com/cve/CVE-2013-5601.html" source="CVE"/>
        <reference ref_id="CVE-2013-5602" ref_url="http://linux.oracle.com/cve/CVE-2013-5602.html" source="CVE"/>
        <reference ref_id="CVE-2013-5604" ref_url="http://linux.oracle.com/cve/CVE-2013-5604.html" source="CVE"/>
        <description>The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:25.244-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.402-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.839-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23434 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:28.580-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:23.471-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:32:56.652-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:32:56.652-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107830"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107236"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107482"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107485"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107652"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23430" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0241: xen security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference ref_id="ELSA-2013:0241-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0241.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4544" ref_url="http://linux.oracle.com/cve/CVE-2012-4544.html" source="CVE"/>
        <description>The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:54.716-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.103-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.463-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23430 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:28.778-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:23.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xen-devel is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:106875"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:107089"/>
          <criterion comment="xen is earlier than 0:3.0.3-142.el5_9.1" test_ref="oval:org.mitre.oval:tst:106931"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23427" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1241: ecryptfs-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference ref_id="ELSA-2011:1241-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1241.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1831" ref_url="http://linux.oracle.com/cve/CVE-2011-1831.html" source="CVE"/>
        <reference ref_id="CVE-2011-1832" ref_url="http://linux.oracle.com/cve/CVE-2011-1832.html" source="CVE"/>
        <reference ref_id="CVE-2011-1834" ref_url="http://linux.oracle.com/cve/CVE-2011-1834.html" source="CVE"/>
        <reference ref_id="CVE-2011-1835" ref_url="http://linux.oracle.com/cve/CVE-2011-1835.html" source="CVE"/>
        <reference ref_id="CVE-2011-1837" ref_url="http://linux.oracle.com/cve/CVE-2011-1837.html" source="CVE"/>
        <reference ref_id="CVE-2011-3145" ref_url="http://linux.oracle.com/cve/CVE-2011-3145.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:19.100-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.725-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:44.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23427 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.404-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:22.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:109224"/>
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:108858"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:109267"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109232"/>
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109063"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23425" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0070: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2012:0070-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0070.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3009" ref_url="http://linux.oracle.com/cve/CVE-2011-3009.html" source="CVE"/>
        <reference ref_id="CVE-2011-4815" ref_url="http://linux.oracle.com/cve/CVE-2011-4815.html" source="CVE"/>
        <description>Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:57.782-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.499-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:44.574-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23425 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.664-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:22.233-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby-ri is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105685"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105618"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105649"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105759"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105180"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105693"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105543"/>
          <criterion comment="ruby is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105632"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-22.el5_7.1" test_ref="oval:org.mitre.oval:tst:105371"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23420" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1820: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2011:1820-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1820.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4601" ref_url="http://linux.oracle.com/cve/CVE-2011-4601.html" source="CVE"/>
        <reference ref_id="CVE-2011-4602" ref_url="http://linux.oracle.com/cve/CVE-2011-4602.html" source="CVE"/>
        <reference ref_id="CVE-2011-4603" ref_url="http://linux.oracle.com/cve/CVE-2011-4603.html" source="CVE"/>
        <description>The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:36.909-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.089-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:43.927-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23420 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.667-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.810-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="finch-devel is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105597"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:104673"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105406"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105588"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105609"/>
          <criterion comment="finch is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105339"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105359"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105284"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_7.4" test_ref="oval:org.mitre.oval:tst:105074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23419" version="22" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0685: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference ref_id="ELSA-2013:0685-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0685.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5195" ref_url="http://linux.oracle.com/cve/CVE-2012-5195.html" source="CVE"/>
        <reference ref_id="CVE-2012-5526" ref_url="http://linux.oracle.com/cve/CVE-2012-5526.html" source="CVE"/>
        <reference ref_id="CVE-2012-6329" ref_url="http://linux.oracle.com/cve/CVE-2012-6329.html" source="CVE"/>
        <reference ref_id="CVE-2013-1667" ref_url="http://linux.oracle.com/cve/CVE-2013-1667.html" source="CVE"/>
        <description>The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:59.140-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.769-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:43.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23419 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.237-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.476-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:32:11.461-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:32:11.461-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-libs is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107323"/>
            <criterion comment="perl-suidperl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107355"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107266"/>
            <criterion comment="perl-Package-Constants is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:107224"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:107291"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:107328"/>
            <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:107324"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:107159"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:107206"/>
            <criterion comment="perl-Archive-Extract is earlier than 1:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:107329"/>
            <criterion comment="perl-version is earlier than 3:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:106922"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:107171"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:106790"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 1:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:106926"/>
            <criterion comment="perl-Module-Loaded is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:107247"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:107244"/>
            <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:107460"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:107295"/>
            <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:107290"/>
            <criterion comment="perl-parent is earlier than 1:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:107225"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:107222"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:107110"/>
            <criterion comment="perl-Pod-Simple is earlier than 1:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:107079"/>
            <criterion comment="perl-Module-Load is earlier than 1:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:107030"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:107271"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:106971"/>
            <criterion comment="perl-IO-Zlib is earlier than 1:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:106723"/>
            <criterion comment="perl-Params-Check is earlier than 1:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:106891"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:106840"/>
            <criterion comment="perl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107346"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:107442"/>
            <criterion comment="perl-Digest-SHA is earlier than 1:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:107377"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:107349"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:106954"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:107319"/>
            <criterion comment="perl-devel is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107366"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:107331"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:106492"/>
            <criterion comment="perl-Module-Build is earlier than 1:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:107340"/>
            <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:107371"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:106903"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:107257"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:107250"/>
            <criterion comment="perl-Object-Accessor is earlier than 1:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:107059"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:106834"/>
            <criterion comment="perl-Log-Message is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:106906"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:107333"/>
            <criterion comment="perl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:107489"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23418" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0677: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:0677-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-0677.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0866" ref_url="http://linux.oracle.com/cve/CVE-2012-0866.html" source="CVE"/>
        <reference ref_id="CVE-2012-0868" ref_url="http://linux.oracle.com/cve/CVE-2012-0868.html" source="CVE"/>
        <description>CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:06.028-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.665-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:43.355-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23418 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.583-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.327-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:105846"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:106158"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:105980"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:105925"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:105886"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:106155"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:105750"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:105648"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:106187"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-4.el5_8" test_ref="oval:org.mitre.oval:tst:106264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23417" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1860: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1860-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1860.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4299" ref_url="http://linux.oracle.com/cve/CVE-2013-4299.html" source="CVE"/>
        <description>Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:26.456-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.579-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:43.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23417 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.620-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.209-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107803"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107717"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107935"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:108041"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107810"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107839"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107263"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107199"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107938"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:108031"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:108017"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.21.1.el5" test_ref="oval:org.mitre.oval:tst:107692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23415" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0131: gnome-vfs2 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnome-vfs2</product>
        </affected>
        <reference ref_id="ELSA-2013:0131-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0131.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2473" ref_url="http://linux.oracle.com/cve/CVE-2009-2473.html" source="CVE"/>
        <description>neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:59.215-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.450-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:43.019-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23415 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.443-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnome-vfs2 is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:106157"/>
          <criterion comment="gnome-vfs2-devel is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:107106"/>
          <criterion comment="gnome-vfs2-smb is earlier than 0:2.16.2-10.el5" test_ref="oval:org.mitre.oval:tst:107105"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23414" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1050: php53 security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference ref_id="ELSA-2013:1050-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1050.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4113" ref_url="http://linux.oracle.com/cve/CVE-2013-4113.html" source="CVE"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:37.821-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.352-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:42.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23414 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.494-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:20.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php53-ldap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107718"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107668"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107762"/>
          <criterion comment="php53 is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107660"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107686"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107712"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107638"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:106972"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107746"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107354"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107778"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107375"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107542"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:106974"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107202"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107658"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107372"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107622"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107649"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:107369"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-13.el5_9.1" test_ref="oval:org.mitre.oval:tst:106912"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23413" version="34" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1087: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1087-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1087.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:21.080-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.148-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:42.500-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23413 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.597-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:20.574-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:28:32.764-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:28:32.764-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104784"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105154"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104813"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104589"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104776"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104970"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105143"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104831"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104990"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104703"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105110"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104729"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105133"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104577"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105038"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23412" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1130: xen security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference ref_id="ELSA-2012:1130-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1130.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2625" ref_url="http://linux.oracle.com/cve/CVE-2012-2625.html" source="CVE"/>
        <description>The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:17.232-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.082-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:42.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23412 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.079-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:20.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:106715"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:106458"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.4" test_ref="oval:org.mitre.oval:tst:106480"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23409" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1407: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1407-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1407.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4194" ref_url="http://linux.oracle.com/cve/CVE-2012-4194.html" source="CVE"/>
        <reference ref_id="CVE-2012-4195" ref_url="http://linux.oracle.com/cve/CVE-2012-4195.html" source="CVE"/>
        <reference ref_id="CVE-2012-4196" ref_url="http://linux.oracle.com/cve/CVE-2012-4196.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:14.233-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.568-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:41.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23409 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.063-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:111234"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:110808"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:111259"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:110878"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:111226"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:110664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23408" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1324: qt4 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>qt4</product>
        </affected>
        <reference ref_id="ELSA-2011:1324-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1324.html" source="VENDOR"/>
        <reference ref_id="CVE-2007-0242" ref_url="http://linux.oracle.com/cve/CVE-2007-0242.html" source="CVE"/>
        <reference ref_id="CVE-2011-3193" ref_url="http://linux.oracle.com/cve/CVE-2011-3193.html" source="CVE"/>
        <description>Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:22.957-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.458-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:41.322-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23408 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.756-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qt4-odbc is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105112"/>
          <criterion comment="qt4-devel is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105343"/>
          <criterion comment="qt4-postgresql is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105051"/>
          <criterion comment="qt4 is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:104792"/>
          <criterion comment="qt4-sqlite is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105055"/>
          <criterion comment="qt4-mysql is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105215"/>
          <criterion comment="qt4-doc is earlier than 0:4.2.1-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105210"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23407" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0716: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:0716-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0716.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1033" ref_url="http://linux.oracle.com/cve/CVE-2012-1033.html" source="CVE"/>
        <reference ref_id="CVE-2012-1667" ref_url="http://linux.oracle.com/cve/CVE-2012-1667.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:05.094-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.342-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:41.137-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23407 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:10.993-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106310"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:105987"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106493"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106287"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106586"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106063"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106623"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106397"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106572"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106100"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:105993"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106194"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106494"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106552"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23406" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0290: java-1.6.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0290-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0290.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:33.860-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.230-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23406 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.821-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108634"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108555"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108524"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108557"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108375"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108267"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:107666"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:107737"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108371"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108352"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108642"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:107892"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108590"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108513"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108553"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23404" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1154: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference ref_id="ELSA-2011:1154-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1154.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2895" ref_url="http://linux.oracle.com/cve/CVE-2011-2895.html" source="CVE"/>
        <description>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:14.663-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.081-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23404 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.913-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:109223"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:109314"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:109209"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:108474"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23403" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1364: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference ref_id="ELSA-2012:1364-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1364.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5166" ref_url="http://linux.oracle.com/cve/CVE-2012-5166.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:43.190-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.988-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.682-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23403 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.990-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:106104"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:107027"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:106617"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:106897"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.4" test_ref="oval:org.mitre.oval:tst:106947"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23402" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1019: libvirt security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2011:1019-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1019.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2511" ref_url="http://linux.oracle.com/cve/CVE-2011-2511.html" source="CVE"/>
        <description>Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:27.918-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.921-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.584-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23402 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.132-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-22.el5" test_ref="oval:org.mitre.oval:tst:105064"/>
          <criterion comment="libvirt is earlier than 0:0.8.2-22.el5" test_ref="oval:org.mitre.oval:tst:104629"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.2-22.el5" test_ref="oval:org.mitre.oval:tst:104834"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23401" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:0060: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0060-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0060.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4108" ref_url="http://linux.oracle.com/cve/CVE-2011-4108.html" source="CVE"/>
        <reference ref_id="CVE-2011-4109" ref_url="http://linux.oracle.com/cve/CVE-2011-4109.html" source="CVE"/>
        <reference ref_id="CVE-2011-4576" ref_url="http://linux.oracle.com/cve/CVE-2011-4576.html" source="CVE"/>
        <reference ref_id="CVE-2011-4619" ref_url="http://linux.oracle.com/cve/CVE-2011-4619.html" source="CVE"/>
        <description>The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:54.552-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.755-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23401 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.676-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:105513"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:105435"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-20.el5_7.1" test_ref="oval:org.mitre.oval:tst:105719"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23399" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1243: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1243-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1243.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Thunderbird; however, affected certificates
issued after this date cannot be re-enabled or used. (BZ#734316)
All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:25.087-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.590-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23399 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.056-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.291-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:27:19.368-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:27:19.368-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-24.el5" test_ref="oval:org.mitre.oval:tst:105138"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.12-2.el6_1" test_ref="oval:org.mitre.oval:tst:105134"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23398" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1778: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2013:1778-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1778.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5576" ref_url="http://linux.oracle.com/cve/CVE-2012-5576.html" source="CVE"/>
        <reference ref_id="CVE-2013-1913" ref_url="http://linux.oracle.com/cve/CVE-2013-1913.html" source="CVE"/>
        <reference ref_id="CVE-2013-1978" ref_url="http://linux.oracle.com/cve/CVE-2013-1978.html" source="CVE"/>
        <description>Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:41.619-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.467-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:39.972-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23398 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.859-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.144-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:26:48.783-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:26:48.783-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:107792"/>
            <criterion comment="gimp-devel is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:107626"/>
            <criterion comment="gimp is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:107704"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:107109"/>
            <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:106866"/>
            <criterion comment="gimp-devel is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:106876"/>
            <criterion comment="gimp is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:107579"/>
            <criterion comment="gimp-help-browser is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:107691"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23397" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1458: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2011:1458-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1458.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4313" ref_url="http://linux.oracle.com/cve/CVE-2011-4313.html" source="CVE"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:38.231-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.380-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:39.828-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23397 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.273-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.003-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:25:55.610-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:25:55.610-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105159"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105433"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105379"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105413"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105504"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105489"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105550"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105516"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105452"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105228"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105481"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105025"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:104636"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23396" version="38" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1812: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2013:1812-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1812.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:41.282-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:39.431-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23396 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.500-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:17.770-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:24:45.507-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:24:45.507-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:107902"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:107396"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23395" version="37" class="patch">
      <metadata>
        <title>ELSA-2012:1258: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>quagga</product>
        </affected>
        <reference ref_id="ELSA-2012:1258-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1258.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1674" ref_url="http://linux.oracle.com/cve/CVE-2010-1674.html" source="CVE"/>
        <reference ref_id="CVE-2011-3323" ref_url="http://linux.oracle.com/cve/CVE-2011-3323.html" source="CVE"/>
        <reference ref_id="CVE-2011-3324" ref_url="http://linux.oracle.com/cve/CVE-2011-3324.html" source="CVE"/>
        <reference ref_id="CVE-2011-3325" ref_url="http://linux.oracle.com/cve/CVE-2011-3325.html" source="CVE"/>
        <reference ref_id="CVE-2011-3326" ref_url="http://linux.oracle.com/cve/CVE-2011-3326.html" source="CVE"/>
        <reference ref_id="CVE-2011-3327" ref_url="http://linux.oracle.com/cve/CVE-2011-3327.html" source="CVE"/>
        <reference ref_id="CVE-2012-0249" ref_url="http://linux.oracle.com/cve/CVE-2012-0249.html" source="CVE"/>
        <reference ref_id="CVE-2012-0250" ref_url="http://linux.oracle.com/cve/CVE-2012-0250.html" source="CVE"/>
        <description>Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:37.577-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.988-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:39.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23395 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:10.871-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:17.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="quagga-devel is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:106562"/>
          <criterion comment="quagga is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:106806"/>
          <criterion comment="quagga-contrib is earlier than 0:0.98.6-7.el5_8.1" test_ref="oval:org.mitre.oval:tst:106770"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23393" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1333: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1333-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1333.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2426" ref_url="http://linux.oracle.com/cve/CVE-2011-2426.html" source="CVE"/>
        <reference ref_id="CVE-2011-2427" ref_url="http://linux.oracle.com/cve/CVE-2011-2427.html" source="CVE"/>
        <reference ref_id="CVE-2011-2428" ref_url="http://linux.oracle.com/cve/CVE-2011-2428.html" source="CVE"/>
        <reference ref_id="CVE-2011-2429" ref_url="http://linux.oracle.com/cve/CVE-2011-2429.html" source="CVE"/>
        <reference ref_id="CVE-2011-2430" ref_url="http://linux.oracle.com/cve/CVE-2011-2430.html" source="CVE"/>
        <reference ref_id="CVE-2011-2444" ref_url="http://linux.oracle.com/cve/CVE-2011-2444.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:34.709-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.727-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:38.679-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23393 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.966-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:17.115-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:24:15.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:24:15.390-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" test_ref="oval:org.mitre.oval:tst:105361"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" test_ref="oval:org.mitre.oval:tst:105078"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23392" version="46" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0981: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0981-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0981.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1682" ref_url="http://linux.oracle.com/cve/CVE-2013-1682.html" source="CVE"/>
        <reference ref_id="CVE-2013-1684" ref_url="http://linux.oracle.com/cve/CVE-2013-1684.html" source="CVE"/>
        <reference ref_id="CVE-2013-1685" ref_url="http://linux.oracle.com/cve/CVE-2013-1685.html" source="CVE"/>
        <reference ref_id="CVE-2013-1686" ref_url="http://linux.oracle.com/cve/CVE-2013-1686.html" source="CVE"/>
        <reference ref_id="CVE-2013-1687" ref_url="http://linux.oracle.com/cve/CVE-2013-1687.html" source="CVE"/>
        <reference ref_id="CVE-2013-1690" ref_url="http://linux.oracle.com/cve/CVE-2013-1690.html" source="CVE"/>
        <reference ref_id="CVE-2013-1692" ref_url="http://linux.oracle.com/cve/CVE-2013-1692.html" source="CVE"/>
        <reference ref_id="CVE-2013-1693" ref_url="http://linux.oracle.com/cve/CVE-2013-1693.html" source="CVE"/>
        <reference ref_id="CVE-2013-1694" ref_url="http://linux.oracle.com/cve/CVE-2013-1694.html" source="CVE"/>
        <reference ref_id="CVE-2013-1697" ref_url="http://linux.oracle.com/cve/CVE-2013-1697.html" source="CVE"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:38.866-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.472-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:38.193-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23392 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.642-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:16.802-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:23:44.388-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:23:44.388-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:106651"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:107383"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:107554"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107304"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107235"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107258"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23390" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1263: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1263-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1263.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3488" ref_url="http://linux.oracle.com/cve/CVE-2012-3488.html" source="CVE"/>
        <reference ref_id="CVE-2012-3489" ref_url="http://linux.oracle.com/cve/CVE-2012-3489.html" source="CVE"/>
        <description>The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:39.191-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.093-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:37.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23390 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.815-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:16.312-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:23:00.983-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:23:00.983-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106554"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106300"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:105880"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106563"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106713"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106599"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106525"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106664"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106690"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106826"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106734"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106818"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106643"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106841"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106823"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106350"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:105953"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106882"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106639"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106850"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:105897"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106669"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23389" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0546: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0546-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0546.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1823" ref_url="http://linux.oracle.com/cve/CVE-2012-1823.html" source="CVE"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:03.959-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:01.862-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:37.419-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23389 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.105-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:16.123-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:21:19.315-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:21:19.315-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105943"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106247"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105747"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105657"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106216"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105572"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105521"/>
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106096"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105902"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106272"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106146"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106126"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105767"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106034"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106248"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106138"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106111"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106217"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105823"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106073"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106110"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106202"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106268"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105973"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105611"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105295"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106280"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106115"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106261"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106020"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105978"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106130"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106277"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106102"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105711"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106266"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105485"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106090"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105608"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105866"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106145"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106245"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106075"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105382"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106024"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23388" version="65" class="patch">
      <metadata>
        <title>ELSA-2011:1386: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:1386-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1386.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4067" ref_url="http://linux.oracle.com/cve/CVE-2009-4067.html" source="CVE"/>
        <reference ref_id="CVE-2011-1160" ref_url="http://linux.oracle.com/cve/CVE-2011-1160.html" source="CVE"/>
        <reference ref_id="CVE-2011-1585" ref_url="http://linux.oracle.com/cve/CVE-2011-1585.html" source="CVE"/>
        <reference ref_id="CVE-2011-1833" ref_url="http://linux.oracle.com/cve/CVE-2011-1833.html" source="CVE"/>
        <reference ref_id="CVE-2011-2484" ref_url="http://linux.oracle.com/cve/CVE-2011-2484.html" source="CVE"/>
        <reference ref_id="CVE-2011-2496" ref_url="http://linux.oracle.com/cve/CVE-2011-2496.html" source="CVE"/>
        <reference ref_id="CVE-2011-2695" ref_url="http://linux.oracle.com/cve/CVE-2011-2695.html" source="CVE"/>
        <reference ref_id="CVE-2011-2699" ref_url="http://linux.oracle.com/cve/CVE-2011-2699.html" source="CVE"/>
        <reference ref_id="CVE-2011-2723" ref_url="http://linux.oracle.com/cve/CVE-2011-2723.html" source="CVE"/>
        <reference ref_id="CVE-2011-2942" ref_url="http://linux.oracle.com/cve/CVE-2011-2942.html" source="CVE"/>
        <reference ref_id="CVE-2011-3131" ref_url="http://linux.oracle.com/cve/CVE-2011-3131.html" source="CVE"/>
        <reference ref_id="CVE-2011-3188" ref_url="http://linux.oracle.com/cve/CVE-2011-3188.html" source="CVE"/>
        <reference ref_id="CVE-2011-3191" ref_url="http://linux.oracle.com/cve/CVE-2011-3191.html" source="CVE"/>
        <reference ref_id="CVE-2011-3209" ref_url="http://linux.oracle.com/cve/CVE-2011-3209.html" source="CVE"/>
        <reference ref_id="CVE-2011-3347" ref_url="http://linux.oracle.com/cve/CVE-2011-3347.html" source="CVE"/>
        <description>A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:24.288-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:01.506-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:36.687-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23388 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.998-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:15.680-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105035"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:104845"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105243"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105265"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:104452"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105404"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105049"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105442"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:104715"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105378"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105183"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.7.1.el5" test_ref="oval:org.mitre.oval:tst:105357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23386" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0133: hplip3 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>hplip3</product>
        </affected>
        <reference ref_id="ELSA-2013:0133-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0133.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2722" ref_url="http://linux.oracle.com/cve/CVE-2011-2722.html" source="CVE"/>
        <description>The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:00.961-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:01.355-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:36.342-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23386 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.166-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:15.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="hplip3-gui is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:106824"/>
          <criterion comment="hplip3-common is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:106819"/>
          <criterion comment="hplip3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:106961"/>
          <criterion comment="hpijs3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:107026"/>
          <criterion comment="hplip3-libs is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:106925"/>
          <criterion comment="libsane-hpaio3 is earlier than 0:3.9.8-15.el5" test_ref="oval:org.mitre.oval:tst:106929"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23385" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0250: elinks security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>elinks</product>
        </affected>
        <reference ref_id="ELSA-2013:0250-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0250.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4545" ref_url="http://linux.oracle.com/cve/CVE-2012-4545.html" source="CVE"/>
        <description>The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:00.115-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:01.287-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:36.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23385 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.248-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:15.300-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:18:27.563-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:18:27.563-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:107140"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:107077"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23383" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1160: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dhcp</product>
        </affected>
        <reference ref_id="ELSA-2011:1160-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1160.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2748" ref_url="http://linux.oracle.com/cve/CVE-2011-2748.html" source="CVE"/>
        <reference ref_id="CVE-2011-2749" ref_url="http://linux.oracle.com/cve/CVE-2011-2749.html" source="CVE"/>
        <description>The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:15.410-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.869-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:35.466-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23383 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.777-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:14.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libdhcp4client is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:105185"/>
            <criterion comment="dhclient is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:105088"/>
            <criterion comment="dhcp-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:104771"/>
            <criterion comment="dhcp is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:104322"/>
            <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:105315"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dhclient is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105282"/>
            <criterion comment="dhcp-devel is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105103"/>
            <criterion comment="dhcp is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:104731"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23382" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0388: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0388-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0388.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0451" ref_url="http://linux.oracle.com/cve/CVE-2012-0451.html" source="CVE"/>
        <reference ref_id="CVE-2012-0455" ref_url="http://linux.oracle.com/cve/CVE-2012-0455.html" source="CVE"/>
        <reference ref_id="CVE-2012-0456" ref_url="http://linux.oracle.com/cve/CVE-2012-0456.html" source="CVE"/>
        <reference ref_id="CVE-2012-0457" ref_url="http://linux.oracle.com/cve/CVE-2012-0457.html" source="CVE"/>
        <reference ref_id="CVE-2012-0458" ref_url="http://linux.oracle.com/cve/CVE-2012-0458.html" source="CVE"/>
        <reference ref_id="CVE-2012-0459" ref_url="http://linux.oracle.com/cve/CVE-2012-0459.html" source="CVE"/>
        <reference ref_id="CVE-2012-0460" ref_url="http://linux.oracle.com/cve/CVE-2012-0460.html" source="CVE"/>
        <reference ref_id="CVE-2012-0461" ref_url="http://linux.oracle.com/cve/CVE-2012-0461.html" source="CVE"/>
        <reference ref_id="CVE-2012-0462" ref_url="http://linux.oracle.com/cve/CVE-2012-0462.html" source="CVE"/>
        <reference ref_id="CVE-2012-0464" ref_url="http://linux.oracle.com/cve/CVE-2012-0464.html" source="CVE"/>
        <description>Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:54.502-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.656-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:35.050-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23382 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.567-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:14.328-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:106065"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:106038"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23381" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0133: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0133-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0133.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:07.589-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.495-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:34.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23381 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.947-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:14.101-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:17:56.051-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:17:56.051-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:107948"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:107814"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23379" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0699: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0699-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0699.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2333" ref_url="http://linux.oracle.com/cve/CVE-2012-2333.html" source="CVE"/>
        <description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:15.692-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.342-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:34.532-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23379 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.479-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:13.833-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:17:24.586-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:17:24.586-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:106317"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:106166"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:105947"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:105544"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:106019"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:106238"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:105827"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23378" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1241: ecryptfs-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference ref_id="ELSA-2011:1241-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1241.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1831" ref_url="http://linux.oracle.com/cve/CVE-2011-1831.html" source="CVE"/>
        <reference ref_id="CVE-2011-1832" ref_url="http://linux.oracle.com/cve/CVE-2011-1832.html" source="CVE"/>
        <reference ref_id="CVE-2011-1834" ref_url="http://linux.oracle.com/cve/CVE-2011-1834.html" source="CVE"/>
        <reference ref_id="CVE-2011-1835" ref_url="http://linux.oracle.com/cve/CVE-2011-1835.html" source="CVE"/>
        <reference ref_id="CVE-2011-1837" ref_url="http://linux.oracle.com/cve/CVE-2011-1837.html" source="CVE"/>
        <reference ref_id="CVE-2011-3145" ref_url="http://linux.oracle.com/cve/CVE-2011-3145.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:22.667-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:34.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23378 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.219-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:13.594-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:16:34.088-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:16:34.088-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:105081"/>
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:105323"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:104371"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105142"/>
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105186"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105099"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23377" version="121" class="patch">
      <metadata>
        <title>ELSA-2013:0958: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0958-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0958.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2449" ref_url="http://linux.oracle.com/cve/CVE-2013-2449.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2458" ref_url="http://linux.oracle.com/cve/CVE-2013-2458.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2460" ref_url="http://linux.oracle.com/cve/CVE-2013-2460.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.	NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:50.541-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:59.578-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:33.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23377 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.471-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:12.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:107196"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:106847"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:107574"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:107571"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.25-2.3.10.4.el5_9" test_ref="oval:org.mitre.oval:tst:106973"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23374" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0621: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0621-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0621.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0268" ref_url="http://linux.oracle.com/cve/CVE-2013-0268.html" source="CVE"/>
        <reference ref_id="CVE-2013-0871" ref_url="http://linux.oracle.com/cve/CVE-2013-0871.html" source="CVE"/>
        <description>Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:53.392-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:59.329-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23374 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.128-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:12.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:106879"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107309"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107255"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107242"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107124"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:106721"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107254"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107195"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:106532"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:106989"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107014"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.3.1.el5" test_ref="oval:org.mitre.oval:tst:107101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23371" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0122: tcl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tcl</product>
        </affected>
        <reference ref_id="ELSA-2013:0122-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0122.html" source="VENDOR"/>
        <reference ref_id="CVE-2007-4772" ref_url="http://linux.oracle.com/cve/CVE-2007-4772.html" source="CVE"/>
        <reference ref_id="CVE-2007-6067" ref_url="http://linux.oracle.com/cve/CVE-2007-6067.html" source="CVE"/>
        <description>Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:02.087-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:59.043-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.228-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23371 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:44.764-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:12.056-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tcl-devel is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:107054"/>
          <criterion comment="tcl is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:106767"/>
          <criterion comment="tcl-html is earlier than 0:8.4.13-6.el5" test_ref="oval:org.mitre.oval:tst:106802"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23370" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1049: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:1049-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1049.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4113" ref_url="http://linux.oracle.com/cve/CVE-2013-4113.html" source="CVE"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:50.250-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.877-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.023-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23370 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:50.137-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:11.777-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:15:45.833-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:15:45.833-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107656"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107142"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107613"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107306"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107335"/>
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107479"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107620"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107707"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107683"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107592"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107693"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107345"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107532"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107413"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107671"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107125"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107643"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107272"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107690"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107681"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107545"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107621"/>
            <criterion comment="php-common is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107598"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107568"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107670"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107700"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107456"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-xml is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107268"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107406"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107661"/>
            <criterion comment="php is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107673"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107590"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107497"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107443"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107667"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107611"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107439"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107633"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107502"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107648"/>
            <criterion comment="php-common is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107418"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107297"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107130"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107604"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:106786"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:107653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23369" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1242: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1242-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1242.html" source="VENDOR"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Firefox; however, affected certificates issued
after this date cannot be re-enabled or used. (BZ#734316)
All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:16.694-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.829-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:31.921-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23369 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:50.722-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:11.677-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:109146"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:109131"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:108933"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:109000"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23366" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1154: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference ref_id="ELSA-2011:1154-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1154.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2895" ref_url="http://linux.oracle.com/cve/CVE-2011-2895.html" source="CVE"/>
        <description>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:20.336-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.661-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:31.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23366 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:50.635-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:11.348-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:12:43.203-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:12:43.203-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:104634"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:105057"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:105151"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:105098"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23365" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1402: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2011:1402-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1402.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3256" ref_url="http://linux.oracle.com/cve/CVE-2011-3256.html" source="CVE"/>
        <description>FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a different vulnerability than CVE-2011-0226.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:21.373-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.589-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:31.507-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23365 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:49.825-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:11.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:105217"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:105173"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:105116"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:105320"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:105407"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:105381"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23364" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0627: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0627-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0627.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0787" ref_url="http://linux.oracle.com/cve/CVE-2013-0787.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:55.098-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.525-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:31.402-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23364 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:44.903-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:11.054-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:12:06.221-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:12:06.221-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:107080"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:107003"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23363" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1165: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1165-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1165.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2982" ref_url="http://linux.oracle.com/cve/CVE-2011-2982.html" source="CVE"/>
        <reference ref_id="CVE-2011-2983" ref_url="http://linux.oracle.com/cve/CVE-2011-2983.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:28.184-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.452-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:31.269-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23363 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:46.626-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:10.945-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-21.el5" test_ref="oval:org.mitre.oval:tst:104847"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23362" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0312: initscripts security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>initscripts</product>
        </affected>
        <reference ref_id="ELSA-2012:0312-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0312.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-1198" ref_url="http://linux.oracle.com/cve/CVE-2008-1198.html" source="CVE"/>
        <description>The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:55.320-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.396-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:31.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23362 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:45.611-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:10.834-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="initscripts is earlier than 0:8.45.42-1.el5" test_ref="oval:org.mitre.oval:tst:105708"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23361" version="33" class="patch">
      <metadata>
        <title>ELSA-2013:1166: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1166-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1166.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2147" ref_url="http://linux.oracle.com/cve/CVE-2013-2147.html" source="CVE"/>
        <reference ref_id="CVE-2013-2164" ref_url="http://linux.oracle.com/cve/CVE-2013-2164.html" source="CVE"/>
        <reference ref_id="CVE-2013-2206" ref_url="http://linux.oracle.com/cve/CVE-2013-2206.html" source="CVE"/>
        <reference ref_id="CVE-2013-2224" ref_url="http://linux.oracle.com/cve/CVE-2013-2224.html" source="CVE"/>
        <reference ref_id="CVE-2013-2232" ref_url="http://linux.oracle.com/cve/CVE-2013-2232.html" source="CVE"/>
        <reference ref_id="CVE-2013-2234" ref_url="http://linux.oracle.com/cve/CVE-2013-2234.html" source="CVE"/>
        <reference ref_id="CVE-2013-2237" ref_url="http://linux.oracle.com/cve/CVE-2013-2237.html" source="CVE"/>
        <description>The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:37.038-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.190-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:30.813-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23361 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:50.436-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:10.410-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107631"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107179"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107566"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107674"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:106804"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107018"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107544"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107743"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107647"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107599"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107581"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.16.1.el5" test_ref="oval:org.mitre.oval:tst:107122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23360" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0646: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2013:0646-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0646.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0272" ref_url="http://linux.oracle.com/cve/CVE-2013-0272.html" source="CVE"/>
        <reference ref_id="CVE-2013-0273" ref_url="http://linux.oracle.com/cve/CVE-2013-0273.html" source="CVE"/>
        <reference ref_id="CVE-2013-0274" ref_url="http://linux.oracle.com/cve/CVE-2013-0274.html" source="CVE"/>
        <description>upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:39.782-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.062-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:30.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23360 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:47.779-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:10.165-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:11:35.817-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:11:35.817-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107381"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107155"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107141"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107267"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107342"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107223"/>
            <criterion comment="finch is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107160"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107292"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:107216"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:106755"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:107376"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:107264"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:107262"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:107313"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:106645"/>
            <criterion comment="finch is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:107334"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:107245"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:107249"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:106865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23359" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0306: krb5 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2012:0306-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0306.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1526" ref_url="http://linux.oracle.com/cve/CVE-2011-1526.html" source="CVE"/>
        <description>ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:57.506-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:57.983-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:30.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23359 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:44.618-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:10.004-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:105674"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:105800"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:105644"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:105743"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:105876"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5" test_ref="oval:org.mitre.oval:tst:105817"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23358" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1123: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1123-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1123.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3817" ref_url="http://linux.oracle.com/cve/CVE-2012-3817.html" source="CVE"/>
        <description>ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:17.953-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:57.874-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:30.334-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23358 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:45.363-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:09.839-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:10:07.556-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:10:07.556-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:105764"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:106561"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:106466"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:106154"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:106296"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:106472"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:106534"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:106729"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:106314"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:106671"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:106688"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:105784"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:106214"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:106762"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23357" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0788: subscription-manager security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subscription-manager</product>
        </affected>
        <reference ref_id="ELSA-2013:0788-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0788.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6137" ref_url="http://linux.oracle.com/cve/CVE-2012-6137.html" source="CVE"/>
        <description>rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:49.053-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:57.786-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:30.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23357 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:43.489-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:09.682-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:08:59.339-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:08:59.339-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:107491"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:106504"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:107048"/>
            <criterion comment="subscription-manager is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:107201"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:107146"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:107419"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:106948"/>
            <criterion comment="subscription-manager is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:107322"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23355" version="62" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1144-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1144.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2130" ref_url="http://linux.oracle.com/cve/CVE-2011-2130.html" source="CVE"/>
        <reference ref_id="CVE-2011-2134" ref_url="http://linux.oracle.com/cve/CVE-2011-2134.html" source="CVE"/>
        <reference ref_id="CVE-2011-2135" ref_url="http://linux.oracle.com/cve/CVE-2011-2135.html" source="CVE"/>
        <reference ref_id="CVE-2011-2136" ref_url="http://linux.oracle.com/cve/CVE-2011-2136.html" source="CVE"/>
        <reference ref_id="CVE-2011-2137" ref_url="http://linux.oracle.com/cve/CVE-2011-2137.html" source="CVE"/>
        <reference ref_id="CVE-2011-2138" ref_url="http://linux.oracle.com/cve/CVE-2011-2138.html" source="CVE"/>
        <reference ref_id="CVE-2011-2139" ref_url="http://linux.oracle.com/cve/CVE-2011-2139.html" source="CVE"/>
        <reference ref_id="CVE-2011-2140" ref_url="http://linux.oracle.com/cve/CVE-2011-2140.html" source="CVE"/>
        <reference ref_id="CVE-2011-2414" ref_url="http://linux.oracle.com/cve/CVE-2011-2414.html" source="CVE"/>
        <reference ref_id="CVE-2011-2415" ref_url="http://linux.oracle.com/cve/CVE-2011-2415.html" source="CVE"/>
        <reference ref_id="CVE-2011-2416" ref_url="http://linux.oracle.com/cve/CVE-2011-2416.html" source="CVE"/>
        <reference ref_id="CVE-2011-2417" ref_url="http://linux.oracle.com/cve/CVE-2011-2417.html" source="CVE"/>
        <reference ref_id="CVE-2011-2424" ref_url="http://linux.oracle.com/cve/CVE-2011-2424.html" source="CVE"/>
        <reference ref_id="CVE-2011-2425" ref_url="http://linux.oracle.com/cve/CVE-2011-2425.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135, CVE-2011-2140, and CVE-2011-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:14.671-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:57.394-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:29.554-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23355 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:44.333-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:09.403-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:08:08.783-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:08:08.783-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el5" test_ref="oval:org.mitre.oval:tst:105076"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el6" test_ref="oval:org.mitre.oval:tst:104953"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23354" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0716: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:0716-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0716.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1033" ref_url="http://linux.oracle.com/cve/CVE-2012-1033.html" source="CVE"/>
        <reference ref_id="CVE-2012-1667" ref_url="http://linux.oracle.com/cve/CVE-2012-1667.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:34.358-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:57.289-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:29.373-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23354 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:48.615-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:09.280-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:07:38.395-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:07:38.395-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:110248"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:110360"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:109958"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:110312"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:109727"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:110389"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:110266"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:110292"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:110345"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:109899"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:109998"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:110339"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:110191"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:110189"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23353" version="34" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1255: libexif security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libexif</product>
        </affected>
        <reference ref_id="ELSA-2012:1255-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1255.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2812" ref_url="http://linux.oracle.com/cve/CVE-2012-2812.html" source="CVE"/>
        <reference ref_id="CVE-2012-2813" ref_url="http://linux.oracle.com/cve/CVE-2012-2813.html" source="CVE"/>
        <reference ref_id="CVE-2012-2814" ref_url="http://linux.oracle.com/cve/CVE-2012-2814.html" source="CVE"/>
        <reference ref_id="CVE-2012-2836" ref_url="http://linux.oracle.com/cve/CVE-2012-2836.html" source="CVE"/>
        <reference ref_id="CVE-2012-2837" ref_url="http://linux.oracle.com/cve/CVE-2012-2837.html" source="CVE"/>
        <reference ref_id="CVE-2012-2840" ref_url="http://linux.oracle.com/cve/CVE-2012-2840.html" source="CVE"/>
        <reference ref_id="CVE-2012-2841" ref_url="http://linux.oracle.com/cve/CVE-2012-2841.html" source="CVE"/>
        <description>Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:40.230-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:57.118-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:29.077-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23353 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:48.249-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:08.926-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:06:25.246-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:06:25.246-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:106696"/>
            <criterion comment="libexif is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:106697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:106120"/>
            <criterion comment="libexif is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:106333"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23352" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0769: glibc security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2013:0769-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0769.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0242" ref_url="http://linux.oracle.com/cve/CVE-2013-0242.html" source="CVE"/>
        <reference ref_id="CVE-2013-1914" ref_url="http://linux.oracle.com/cve/CVE-2013-1914.html" source="CVE"/>
        <reference ref_id="CVE-2013-1915" ref_url="http://linux.oracle.com/cve/CVE-2013-1915.html" source="CVE"/>
        <description>ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:34.562-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:57.018-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:28.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23352 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:46.243-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:08.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-common is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:107220"/>
          <criterion comment="nscd is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:107407"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:107177"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:107399"/>
          <criterion comment="glibc is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:107338"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-107.el5_9.4" test_ref="oval:org.mitre.oval:tst:106666"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23351" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1090: nss and nspr security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2012:1090-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1090.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0441" ref_url="http://linux.oracle.com/cve/CVE-2012-0441.html" source="CVE"/>
        <description>The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:04.678-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:56.947-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:28.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23351 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:48.401-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:08.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr-devel is earlier than 0:4.9.1-4.el5_8" test_ref="oval:org.mitre.oval:tst:106234"/>
          <criterion comment="nspr is earlier than 0:4.9.1-4.el5_8" test_ref="oval:org.mitre.oval:tst:106144"/>
          <criterion comment="nss-tools is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:106411"/>
          <criterion comment="nss is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:106590"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:105990"/>
          <criterion comment="nss-devel is earlier than 0:3.13.5-4.el5_8" test_ref="oval:org.mitre.oval:tst:106044"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23350" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1089: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2011:1089-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1089.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2503" ref_url="http://linux.oracle.com/cve/CVE-2011-2503.html" source="CVE"/>
        <description>The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:16.533-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:56.862-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:28.651-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23350 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:50.548-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:08.328-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="systemtap-testsuite is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:104995"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:104902"/>
          <criterion comment="systemtap is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:104994"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:104755"/>
          <criterion comment="systemtap-client is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:104240"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:105069"/>
          <criterion comment="systemtap-server is earlier than 0:1.3-9.el5" test_ref="oval:org.mitre.oval:tst:104820"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23349" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0170: libuser security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libuser</product>
        </affected>
        <reference ref_id="ELSA-2011:0170-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0170.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0002" ref_url="http://linux.oracle.com/cve/CVE-2011-0002.html" source="CVE"/>
        <description>libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:26.248-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:56.784-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:28.539-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23349 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:51.241-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:08.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libuser-devel is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:108354"/>
            <criterion comment="libuser is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:107883"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libuser-devel is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108082"/>
            <criterion comment="libuser is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108314"/>
            <criterion comment="libuser-python is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108232"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23348" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0132: autofs security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>autofs</product>
        </affected>
        <reference ref_id="ELSA-2013:0132-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0132.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2697" ref_url="http://linux.oracle.com/cve/CVE-2012-2697.html" source="CVE"/>
        <description>Unspecified vulnerability in autofs, as used in Red Hat Enterprise Linux (RHEL) 5, allows local users to cause a denial of service (autofs crash and delayed mounts) or prevent "mount expiration" via unspecified vectors related to "using an LDAP-based automount map."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:00.759-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:56.725-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:28.432-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23348 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:43.820-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:08.080-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="autofs is earlier than 1:5.0.1-0.rc2.177.el5" test_ref="oval:org.mitre.oval:tst:106917"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23347" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0668: boost security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>boost</product>
        </affected>
        <reference ref_id="ELSA-2013:0668-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0668.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2677" ref_url="http://linux.oracle.com/cve/CVE-2012-2677.html" source="CVE"/>
        <description>Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:55.754-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:56.615-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:28.258-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23347 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:45.197-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:07.904-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:05:46.410-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:05:46.410-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="boost-graph-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107005"/>
            <criterion comment="boost-graph-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107300"/>
            <criterion comment="boost-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107341"/>
            <criterion comment="boost-test is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107380"/>
            <criterion comment="boost-graph is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:106909"/>
            <criterion comment="boost is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:106738"/>
            <criterion comment="boost-mpich2-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107061"/>
            <criterion comment="boost-wave is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107289"/>
            <criterion comment="boost-filesystem is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107219"/>
            <criterion comment="boost-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107339"/>
            <criterion comment="boost-thread is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:106993"/>
            <criterion comment="boost-mpich2-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:106822"/>
            <criterion comment="boost-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107078"/>
            <criterion comment="boost-static is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107228"/>
            <criterion comment="boost-doc is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:106542"/>
            <criterion comment="boost-regex is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107368"/>
            <criterion comment="boost-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107229"/>
            <criterion comment="boost-openmpi-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107363"/>
            <criterion comment="boost-serialization is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:106996"/>
            <criterion comment="boost-system is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107239"/>
            <criterion comment="boost-iostreams is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107280"/>
            <criterion comment="boost-signals is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107188"/>
            <criterion comment="boost-program-options is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107277"/>
            <criterion comment="boost-openmpi-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107283"/>
            <criterion comment="boost-date-time is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:106386"/>
            <criterion comment="boost-math is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:107279"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="boost is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:107260"/>
            <criterion comment="boost-doc is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:107259"/>
            <criterion comment="boost-devel is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:107063"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23344" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0999: rsync security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>rsync</product>
        </affected>
        <reference ref_id="ELSA-2011:0999-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0999.html" source="VENDOR"/>
        <reference ref_id="CVE-2007-6200" ref_url="http://linux.oracle.com/cve/CVE-2007-6200.html" source="CVE"/>
        <description>Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:26.568-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:56.334-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:27.760-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23344 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:49.700-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:07.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="rsync is earlier than 0:3.0.6-4.el5" test_ref="oval:org.mitre.oval:tst:105105"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23341" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0523: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference ref_id="ELSA-2012:0523-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0523.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3048" ref_url="http://linux.oracle.com/cve/CVE-2011-3048.html" source="CVE"/>
        <description>The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:50.777-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:55.752-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:26.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23341 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:47.588-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:06.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:105918"/>
            <criterion comment="libpng is earlier than 2:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:105797"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-static is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:105321"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:105883"/>
            <criterion comment="libpng is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:105581"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23339" version="49" class="patch">
      <metadata>
        <title>ELSA-2011:0860: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2011:0860-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0860.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0863" ref_url="http://linux.oracle.com/cve/CVE-2011-0863.html" source="CVE"/>
        <reference ref_id="CVE-2011-0864" ref_url="http://linux.oracle.com/cve/CVE-2011-0864.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0868" ref_url="http://linux.oracle.com/cve/CVE-2011-0868.html" source="CVE"/>
        <reference ref_id="CVE-2011-0869" ref_url="http://linux.oracle.com/cve/CVE-2011-0869.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:22.779-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:55.396-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:26.183-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23339 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:51.474-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:05.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104735"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104213"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104537"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104892"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105041"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104925"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105017"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104329"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104835"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104949"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104379"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104647"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23338" version="26" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0079: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0079-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0079.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3659" ref_url="http://linux.oracle.com/cve/CVE-2011-3659.html" source="CVE"/>
        <reference ref_id="CVE-2011-3670" ref_url="http://linux.oracle.com/cve/CVE-2011-3670.html" source="CVE"/>
        <reference ref_id="CVE-2012-0442" ref_url="http://linux.oracle.com/cve/CVE-2012-0442.html" source="CVE"/>
        <reference ref_id="CVE-2012-0444" ref_url="http://linux.oracle.com/cve/CVE-2012-0444.html" source="CVE"/>
        <reference ref_id="CVE-2012-0449" ref_url="http://linux.oracle.com/cve/CVE-2012-0449.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:58.561-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:55.254-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:25.899-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23338 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:45.819-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:05.525-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:03:23.815-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:03:23.815-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:105749"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:104974"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:105560"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:105587"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:105595"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:105292"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23337" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1779: mod_nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>mod_nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1779-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1779.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4566" ref_url="http://linux.oracle.com/cve/CVE-2013-4566.html" source="CVE"/>
        <description>mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:24.278-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:55.191-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:25.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23337 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:45.498-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:05.394-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:02:36.625-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:02:36.625-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="mod_nss is earlier than 0:1.0.8-8.el5_10" test_ref="oval:org.mitre.oval:tst:107843"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="mod_nss is earlier than 0:1.0.8-19.el6_5" test_ref="oval:org.mitre.oval:tst:107838"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23336" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0731: expat security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>expat</product>
        </affected>
        <reference ref_id="ELSA-2012:0731-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0731.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0876" ref_url="http://linux.oracle.com/cve/CVE-2012-0876.html" source="CVE"/>
        <reference ref_id="CVE-2012-1148" ref_url="http://linux.oracle.com/cve/CVE-2012-1148.html" source="CVE"/>
        <description>Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:01.430-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:55.111-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:25.634-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23336 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:51.147-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:05.212-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:01:54.701-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:01:54.701-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="expat-devel is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:106445"/>
            <criterion comment="expat is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:106239"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="expat-devel is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:106475"/>
            <criterion comment="expat is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:106476"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23334" version="46" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0710: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0710-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0710.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3101" ref_url="http://linux.oracle.com/cve/CVE-2011-3101.html" source="CVE"/>
        <reference ref_id="CVE-2012-1937" ref_url="http://linux.oracle.com/cve/CVE-2012-1937.html" source="CVE"/>
        <reference ref_id="CVE-2012-1938" ref_url="http://linux.oracle.com/cve/CVE-2012-1938.html" source="CVE"/>
        <reference ref_id="CVE-2012-1939" ref_url="http://linux.oracle.com/cve/CVE-2012-1939.html" source="CVE"/>
        <reference ref_id="CVE-2012-1940" ref_url="http://linux.oracle.com/cve/CVE-2012-1940.html" source="CVE"/>
        <reference ref_id="CVE-2012-1941" ref_url="http://linux.oracle.com/cve/CVE-2012-1941.html" source="CVE"/>
        <reference ref_id="CVE-2012-1944" ref_url="http://linux.oracle.com/cve/CVE-2012-1944.html" source="CVE"/>
        <reference ref_id="CVE-2012-1945" ref_url="http://linux.oracle.com/cve/CVE-2012-1945.html" source="CVE"/>
        <reference ref_id="CVE-2012-1946" ref_url="http://linux.oracle.com/cve/CVE-2012-1946.html" source="CVE"/>
        <reference ref_id="CVE-2012-1947" ref_url="http://linux.oracle.com/cve/CVE-2012-1947.html" source="CVE"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:19.247-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:54.806-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:25.072-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23334 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:48.944-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:04.929-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:01:01.817-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:01:01.817-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:106391"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:106103"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:106361"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:105899"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:106407"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:106383"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23333" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1061: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1061-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1061.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3375" ref_url="http://linux.oracle.com/cve/CVE-2012-3375.html" source="CVE"/>
        <description>The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:21:56.166-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:54.729-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:24.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23333 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:47.960-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:04.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106663"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106218"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106219"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106400"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106524"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106420"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106309"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106727"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106704"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106119"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106502"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.11.1.el5" test_ref="oval:org.mitre.oval:tst:106598"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23332" version="77" class="patch">
      <metadata>
        <title>ELSA-2011:1384: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2011:1384-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1384.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3389" ref_url="http://linux.oracle.com/cve/CVE-2011-3389.html" source="CVE"/>
        <reference ref_id="CVE-2011-3516" ref_url="http://linux.oracle.com/cve/CVE-2011-3516.html" source="CVE"/>
        <reference ref_id="CVE-2011-3521" ref_url="http://linux.oracle.com/cve/CVE-2011-3521.html" source="CVE"/>
        <reference ref_id="CVE-2011-3544" ref_url="http://linux.oracle.com/cve/CVE-2011-3544.html" source="CVE"/>
        <reference ref_id="CVE-2011-3545" ref_url="http://linux.oracle.com/cve/CVE-2011-3545.html" source="CVE"/>
        <reference ref_id="CVE-2011-3546" ref_url="http://linux.oracle.com/cve/CVE-2011-3546.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3549" ref_url="http://linux.oracle.com/cve/CVE-2011-3549.html" source="CVE"/>
        <reference ref_id="CVE-2011-3550" ref_url="http://linux.oracle.com/cve/CVE-2011-3550.html" source="CVE"/>
        <reference ref_id="CVE-2011-3551" ref_url="http://linux.oracle.com/cve/CVE-2011-3551.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3553" ref_url="http://linux.oracle.com/cve/CVE-2011-3553.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <reference ref_id="CVE-2011-3557" ref_url="http://linux.oracle.com/cve/CVE-2011-3557.html" source="CVE"/>
        <reference ref_id="CVE-2011-3558" ref_url="http://linux.oracle.com/cve/CVE-2011-3558.html" source="CVE"/>
        <reference ref_id="CVE-2011-3560" ref_url="http://linux.oracle.com/cve/CVE-2011-3560.html" source="CVE"/>
        <reference ref_id="CVE-2011-3561" ref_url="http://linux.oracle.com/cve/CVE-2011-3561.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:59.549-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:54.335-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:24.157-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23332 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:50.867-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:04.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109236"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109255"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109121"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109257"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109328"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109273"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109113"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109329"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109188"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108744"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109323"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109466"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23331" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0474: tomcat5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference ref_id="ELSA-2012:0474-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0474.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4858" ref_url="http://linux.oracle.com/cve/CVE-2011-4858.html" source="CVE"/>
        <reference ref_id="CVE-2012-0022" ref_url="http://linux.oracle.com/cve/CVE-2012-0022.html" source="CVE"/>
        <description>Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:47.282-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:54.243-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:23.966-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23331 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:49.120-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:04.171-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105670"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105462"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105735"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105807"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:106128"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105620"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105307"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105130"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105721"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105852"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.31.el5_8" test_ref="oval:org.mitre.oval:tst:105491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23330" version="65" class="patch">
      <metadata>
        <title>ELSA-2011:0927: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0927-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0927.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4649" ref_url="http://linux.oracle.com/cve/CVE-2010-4649.html" source="CVE"/>
        <reference ref_id="CVE-2011-0695" ref_url="http://linux.oracle.com/cve/CVE-2011-0695.html" source="CVE"/>
        <reference ref_id="CVE-2011-0711" ref_url="http://linux.oracle.com/cve/CVE-2011-0711.html" source="CVE"/>
        <reference ref_id="CVE-2011-1044" ref_url="http://linux.oracle.com/cve/CVE-2011-1044.html" source="CVE"/>
        <reference ref_id="CVE-2011-1182" ref_url="http://linux.oracle.com/cve/CVE-2011-1182.html" source="CVE"/>
        <reference ref_id="CVE-2011-1573" ref_url="http://linux.oracle.com/cve/CVE-2011-1573.html" source="CVE"/>
        <reference ref_id="CVE-2011-1576" ref_url="http://linux.oracle.com/cve/CVE-2011-1576.html" source="CVE"/>
        <reference ref_id="CVE-2011-1593" ref_url="http://linux.oracle.com/cve/CVE-2011-1593.html" source="CVE"/>
        <reference ref_id="CVE-2011-1745" ref_url="http://linux.oracle.com/cve/CVE-2011-1745.html" source="CVE"/>
        <reference ref_id="CVE-2011-1746" ref_url="http://linux.oracle.com/cve/CVE-2011-1746.html" source="CVE"/>
        <reference ref_id="CVE-2011-1776" ref_url="http://linux.oracle.com/cve/CVE-2011-1776.html" source="CVE"/>
        <reference ref_id="CVE-2011-1936" ref_url="http://linux.oracle.com/cve/CVE-2011-1936.html" source="CVE"/>
        <reference ref_id="CVE-2011-2022" ref_url="http://linux.oracle.com/cve/CVE-2011-2022.html" source="CVE"/>
        <reference ref_id="CVE-2011-2213" ref_url="http://linux.oracle.com/cve/CVE-2011-2213.html" source="CVE"/>
        <reference ref_id="CVE-2011-2492" ref_url="http://linux.oracle.com/cve/CVE-2011-2492.html" source="CVE"/>
        <description>The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:16.860-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.944-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:23.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23330 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:43.277-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:03.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104945"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104719"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104919"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104891"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104912"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104524"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:105054"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:105147"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:105124"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:105136"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104164"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.19.1.el5" test_ref="oval:org.mitre.oval:tst:104158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23328" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1282: nss and nspr security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nspr</product>
        </affected>
        <reference ref_id="ELSA-2011:1282-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1282.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities.
It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update renders any HTTPS certificates signed by that CA
as untrusted. This covers all uses of the certificates, including SSL,
S/MIME, and code signing. (BZ#734316)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
These updated packages upgrade NSS to version 3.12.10 on Red Hat Enterprise
Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Red Hat
Enterprise Linux 4 and 5, as required by the NSS update. The packages for
Red Hat Enterprise Linux 6 include a backported patch.
All NSS and NSPR users should upgrade to these updated packages, which
correct this issue. After installing the update, applications using NSS and
NSPR must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:24.807-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.805-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:23.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23328 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:45.938-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:03.335-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:00:12.489-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:00:12.489-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nspr is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:104962"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:105234"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:105288"/>
            <criterion comment="nss-tools is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:104928"/>
            <criterion comment="nss is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:104539"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:104698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:105174"/>
            <criterion comment="nss-tools is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:105229"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:105253"/>
            <criterion comment="nss is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:105256"/>
            <criterion comment="nss-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:105249"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23327" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0301: ImageMagick security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference ref_id="ELSA-2012:0301-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0301.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4167" ref_url="http://linux.oracle.com/cve/CVE-2010-4167.html" source="CVE"/>
        <description>Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:58.139-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.739-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:22.983-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23327 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:46.496-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:03.224-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:105849"/>
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:105868"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:105892"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:105623"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-12.el5" test_ref="oval:org.mitre.oval:tst:105556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23326" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0180: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2013:0180-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0180.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2749" ref_url="http://linux.oracle.com/cve/CVE-2012-2749.html" source="CVE"/>
        <reference ref_id="CVE-2012-5611" ref_url="http://linux.oracle.com/cve/CVE-2012-5611.html" source="CVE"/>
        <description>Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:06.183-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.660-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:22.838-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23326 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:46.084-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:03.106-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-test is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:106674"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:106148"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:106982"/>
          <criterion comment="mysql is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:107012"/>
          <criterion comment="mysql-server is earlier than 0:5.0.95-5.el5_9" test_ref="oval:org.mitre.oval:tst:106777"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23325" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0270: jakarta-commons-httpclient security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference ref_id="ELSA-2013:0270-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0270.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5783" ref_url="http://linux.oracle.com/cve/CVE-2012-5783.html" source="CVE"/>
        <description>Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:57.844-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.586-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:22.724-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23325 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:43.939-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:02.956-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:59:05.670-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:59:05.670-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:106803"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:106838"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:106978"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:106919"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:107123"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:106899"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:107066"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:106744"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23324" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1005: sysstat security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sysstat</product>
        </affected>
        <reference ref_id="ELSA-2011:1005-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1005.html" source="VENDOR"/>
        <reference ref_id="CVE-2007-3852" ref_url="http://linux.oracle.com/cve/CVE-2007-3852.html" source="CVE"/>
        <description>The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:18.273-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.527-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:22.640-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23324 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:46.730-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:02.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sysstat is earlier than 0:7.0.2-11.el5" test_ref="oval:org.mitre.oval:tst:105165"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23322" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1459: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference ref_id="ELSA-2011:1459-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1459.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4313" ref_url="http://linux.oracle.com/cve/CVE-2011-4313.html" source="CVE"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:23.454-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.187-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:22.022-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23322 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:45.029-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:02.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:105468"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:105037"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:105208"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:105347"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_7.4" test_ref="oval:org.mitre.oval:tst:105363"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23321" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0274: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0274-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0274.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:57.282-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.107-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:21.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23321 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:33.455-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:56.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:106326"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:107165"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:107134"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:107170"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.35.1.11.8.el5_9" test_ref="oval:org.mitre.oval:tst:106896"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23320" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1156: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:1156-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1156.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1896" ref_url="http://linux.oracle.com/cve/CVE-2013-1896.html" source="CVE"/>
        <description>mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:39.447-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:53.033-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:21.753-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23320 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:23.891-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:02.472-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:58:13.734-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:58:13.734-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="mod_ssl is earlier than 1:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:106854"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:107584"/>
            <criterion comment="httpd is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:107600"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:107008"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:107727"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:107758"/>
            <criterion comment="httpd is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:107719"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:107756"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:107432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23318" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0465: samba security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2012:0465-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0465.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1182" ref_url="http://linux.oracle.com/cve/CVE-2012-1182.html" source="CVE"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:48.702-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:52.877-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:21.452-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23318 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:23.767-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:02.266-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:57:17.294-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:57:17.294-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:105999"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:105517"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:105905"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:105672"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:105601"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:106060"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:106023"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105449"/>
            <criterion comment="samba is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105731"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105104"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105582"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:106067"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:106049"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105233"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105981"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105806"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:106027"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:105884"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23317" version="85" class="patch">
      <metadata>
        <title>ELSA-2012:1350: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1350-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1350.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1956" ref_url="http://linux.oracle.com/cve/CVE-2012-1956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3982" ref_url="http://linux.oracle.com/cve/CVE-2012-3982.html" source="CVE"/>
        <reference ref_id="CVE-2012-3986" ref_url="http://linux.oracle.com/cve/CVE-2012-3986.html" source="CVE"/>
        <reference ref_id="CVE-2012-3988" ref_url="http://linux.oracle.com/cve/CVE-2012-3988.html" source="CVE"/>
        <reference ref_id="CVE-2012-3990" ref_url="http://linux.oracle.com/cve/CVE-2012-3990.html" source="CVE"/>
        <reference ref_id="CVE-2012-3991" ref_url="http://linux.oracle.com/cve/CVE-2012-3991.html" source="CVE"/>
        <reference ref_id="CVE-2012-3992" ref_url="http://linux.oracle.com/cve/CVE-2012-3992.html" source="CVE"/>
        <reference ref_id="CVE-2012-3993" ref_url="http://linux.oracle.com/cve/CVE-2012-3993.html" source="CVE"/>
        <reference ref_id="CVE-2012-3994" ref_url="http://linux.oracle.com/cve/CVE-2012-3994.html" source="CVE"/>
        <reference ref_id="CVE-2012-3995" ref_url="http://linux.oracle.com/cve/CVE-2012-3995.html" source="CVE"/>
        <reference ref_id="CVE-2012-4179" ref_url="http://linux.oracle.com/cve/CVE-2012-4179.html" source="CVE"/>
        <reference ref_id="CVE-2012-4180" ref_url="http://linux.oracle.com/cve/CVE-2012-4180.html" source="CVE"/>
        <reference ref_id="CVE-2012-4181" ref_url="http://linux.oracle.com/cve/CVE-2012-4181.html" source="CVE"/>
        <reference ref_id="CVE-2012-4182" ref_url="http://linux.oracle.com/cve/CVE-2012-4182.html" source="CVE"/>
        <reference ref_id="CVE-2012-4183" ref_url="http://linux.oracle.com/cve/CVE-2012-4183.html" source="CVE"/>
        <reference ref_id="CVE-2012-4184" ref_url="http://linux.oracle.com/cve/CVE-2012-4184.html" source="CVE"/>
        <reference ref_id="CVE-2012-4185" ref_url="http://linux.oracle.com/cve/CVE-2012-4185.html" source="CVE"/>
        <reference ref_id="CVE-2012-4186" ref_url="http://linux.oracle.com/cve/CVE-2012-4186.html" source="CVE"/>
        <reference ref_id="CVE-2012-4187" ref_url="http://linux.oracle.com/cve/CVE-2012-4187.html" source="CVE"/>
        <reference ref_id="CVE-2012-4188" ref_url="http://linux.oracle.com/cve/CVE-2012-4188.html" source="CVE"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:13.678-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:52.485-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:20.638-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23317 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:22.339-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:02.143-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:111255"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:110564"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:111021"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:111248"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:111245"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:111166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23316" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1349: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>rpm</product>
        </affected>
        <reference ref_id="ELSA-2011:1349-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1349.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3378" ref_url="http://linux.oracle.com/cve/CVE-2011-3378.html" source="CVE"/>
        <description>RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:28.348-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:52.396-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:20.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23316 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:21.843-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:02.017-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:55:55.351-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:55:55.351-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:105091"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:104690"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:105128"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:105070"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:105246"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:105201"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:105244"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:105277"/>
            <criterion comment="rpm is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:104733"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:104955"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:105257"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:104918"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:105236"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:104693"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23315" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0372: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0372-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0372.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0609" ref_url="http://linux.oracle.com/cve/CVE-2011-0609.html" source="CVE"/>
        <description>Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:20.318-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:52.324-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:20.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23315 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:26.628-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:01.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el5" test_ref="oval:org.mitre.oval:tst:108390"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el6" test_ref="oval:org.mitre.oval:tst:108659"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23314" version="65" class="patch">
      <metadata>
        <title>ELSA-2012:1483: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1483-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1483.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4201" ref_url="http://linux.oracle.com/cve/CVE-2012-4201.html" source="CVE"/>
        <reference ref_id="CVE-2012-4202" ref_url="http://linux.oracle.com/cve/CVE-2012-4202.html" source="CVE"/>
        <reference ref_id="CVE-2012-4207" ref_url="http://linux.oracle.com/cve/CVE-2012-4207.html" source="CVE"/>
        <reference ref_id="CVE-2012-4209" ref_url="http://linux.oracle.com/cve/CVE-2012-4209.html" source="CVE"/>
        <reference ref_id="CVE-2012-4214" ref_url="http://linux.oracle.com/cve/CVE-2012-4214.html" source="CVE"/>
        <reference ref_id="CVE-2012-4215" ref_url="http://linux.oracle.com/cve/CVE-2012-4215.html" source="CVE"/>
        <reference ref_id="CVE-2012-4216" ref_url="http://linux.oracle.com/cve/CVE-2012-4216.html" source="CVE"/>
        <reference ref_id="CVE-2012-5829" ref_url="http://linux.oracle.com/cve/CVE-2012-5829.html" source="CVE"/>
        <reference ref_id="CVE-2012-5830" ref_url="http://linux.oracle.com/cve/CVE-2012-5830.html" source="CVE"/>
        <reference ref_id="CVE-2012-5833" ref_url="http://linux.oracle.com/cve/CVE-2012-5833.html" source="CVE"/>
        <reference ref_id="CVE-2012-5835" ref_url="http://linux.oracle.com/cve/CVE-2012-5835.html" source="CVE"/>
        <reference ref_id="CVE-2012-5839" ref_url="http://linux.oracle.com/cve/CVE-2012-5839.html" source="CVE"/>
        <reference ref_id="CVE-2012-5840" ref_url="http://linux.oracle.com/cve/CVE-2012-5840.html" source="CVE"/>
        <reference ref_id="CVE-2012-5841" ref_url="http://linux.oracle.com/cve/CVE-2012-5841.html" source="CVE"/>
        <reference ref_id="CVE-2012-5842" ref_url="http://linux.oracle.com/cve/CVE-2012-5842.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:11.905-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:52.018-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:19.789-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23314 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:26.518-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:01.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:111273"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:110709"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23313" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0580: cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference ref_id="ELSA-2013:0580-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0580.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5519" ref_url="http://linux.oracle.com/cve/CVE-2012-5519.html" source="CVE"/>
        <description>CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:00.359-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:51.938-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:19.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23313 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:21.152-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:01.405-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:54:41.702-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:54:41.702-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cups-php is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:107217"/>
            <criterion comment="cups-lpd is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:107148"/>
            <criterion comment="cups-devel is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:106764"/>
            <criterion comment="cups is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:106939"/>
            <criterion comment="cups-libs is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:106338"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cups-devel is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:106800"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:106616"/>
            <criterion comment="cups is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:106791"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:107087"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23312" version="37" class="patch">
      <metadata>
        <title>ELSA-2011:1159: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1159-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1159.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0311" ref_url="http://linux.oracle.com/cve/CVE-2011-0311.html" source="CVE"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-3387" ref_url="http://linux.oracle.com/cve/CVE-2011-3387.html" source="CVE"/>
        <description>The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:23.497-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:51.668-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:19.277-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23312 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:25.498-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:01.245-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104189"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105162"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104774"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105139"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104987"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104969"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.10-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104683"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23311" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1385: kdelibs and kdelibs3 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
          <product>kdelibs3</product>
        </affected>
        <reference ref_id="ELSA-2011:1385-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1385.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3365" ref_url="http://linux.oracle.com/cve/CVE-2011-3365.html" source="CVE"/>
        <description>The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:27.740-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:51.558-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:19.160-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23311 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:24.689-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:01.149-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:53:46.022-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:53:46.022-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:105199"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:105071"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:105367"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="kdelibs3-apidocs is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:105301"/>
            <criterion comment="kdelibs3-devel is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:104932"/>
            <criterion comment="kdelibs3 is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:105193"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23309" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0093: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0093-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0093.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0830" ref_url="http://linux.oracle.com/cve/CVE-2012-0830.html" source="CVE"/>
        <description>The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.	 NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:59.349-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:51.221-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:18.829-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23309 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:24.222-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:00.871-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:52:59.600-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:52:59.600-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:104961"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105391"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105346"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:104791"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105297"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105469"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105397"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105688"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105612"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105763"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105392"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105633"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105699"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105785"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105742"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105500"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105511"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105746"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105396"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105564"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105476"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105723"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105757"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105713"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105411"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:105409"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105779"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105701"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105529"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:104857"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105776"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105716"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105621"/>
            <criterion comment="php is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105645"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105460"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105456"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105566"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:104807"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105093"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105325"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105769"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105659"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105668"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105636"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:105421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23307" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1378: postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference ref_id="ELSA-2011:1378-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1378.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2483" ref_url="http://linux.oracle.com/cve/CVE-2011-2483.html" source="CVE"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:37.440-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:50.995-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:18.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23307 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:23.487-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:00.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105298"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105125"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105293"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:104624"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105376"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105380"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:104812"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105322"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105108"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:104956"/>
          <criterion comment="postgresql84 is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105365"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.9-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105314"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23306" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1196: system-config-printer security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>system-config-printer</product>
        </affected>
        <reference ref_id="ELSA-2011:1196-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1196.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2899" ref_url="http://linux.oracle.com/cve/CVE-2011-2899.html" source="CVE"/>
        <description>pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrary commands via shell metacharacters in the (1) NetBIOS or (2) workgroup name, which are not properly handled when searching for network printers.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:14.531-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:50.898-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:18.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23306 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:20.636-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:00.523-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="system-config-printer-libs is earlier than 0:0.7.32.10-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:104983"/>
          <criterion comment="system-config-printer is earlier than 0:0.7.32.10-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105195"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23305" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0016: gnupg security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnupg</product>
        </affected>
        <reference ref_id="ELSA-2014:0016-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0016.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4576" ref_url="http://linux.oracle.com/cve/CVE-2013-4576.html" source="CVE"/>
        <description>GnuPG 1.x before 1.4.16 generates RSA keys using sequences of introductions with certain patterns that introduce a side channel, which allows physically proximate attackers to extract RSA keys via a chosen-ciphertext attack and acoustic cryptanalysis during decryption. NOTE: applications are not typically expected to protect themselves from acoustic side-channel attacks, since this is arguably the responsibility of the physical device. Accordingly, issues of this type would not normally receive a CVE identifier. However, for this issue, the developer has specified a security policy in which GnuPG should offer side-channel resistance, and developer-specified security-policy violations are within the scope of CVE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:11.672-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:50.805-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:18.340-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23305 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:25.603-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:00.445-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="gnupg is earlier than 0:1.4.5-18.el5_10.1" test_ref="oval:org.mitre.oval:tst:107506"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23304" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0518: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference ref_id="ELSA-2012:0518-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0518.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2110" ref_url="http://linux.oracle.com/cve/CVE-2012-2110.html" source="CVE"/>
        <description>The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:47.053-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:50.686-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:18.223-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23304 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:24.812-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:00.341-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:50:12.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:50:12.723-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:106058"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:105913"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:106131"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" test_ref="oval:org.mitre.oval:tst:105756"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:105954"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:105888"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:105360"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:105908"/>
            <criterion comment="openssl098e is earlier than 0:0.9.8e-17.el6_2.2" test_ref="oval:org.mitre.oval:tst:106124"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23301" version="62" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0467: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2012:0467-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0467.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1126" ref_url="http://linux.oracle.com/cve/CVE-2012-1126.html" source="CVE"/>
        <reference ref_id="CVE-2012-1127" ref_url="http://linux.oracle.com/cve/CVE-2012-1127.html" source="CVE"/>
        <reference ref_id="CVE-2012-1130" ref_url="http://linux.oracle.com/cve/CVE-2012-1130.html" source="CVE"/>
        <reference ref_id="CVE-2012-1131" ref_url="http://linux.oracle.com/cve/CVE-2012-1131.html" source="CVE"/>
        <reference ref_id="CVE-2012-1132" ref_url="http://linux.oracle.com/cve/CVE-2012-1132.html" source="CVE"/>
        <reference ref_id="CVE-2012-1134" ref_url="http://linux.oracle.com/cve/CVE-2012-1134.html" source="CVE"/>
        <reference ref_id="CVE-2012-1136" ref_url="http://linux.oracle.com/cve/CVE-2012-1136.html" source="CVE"/>
        <reference ref_id="CVE-2012-1137" ref_url="http://linux.oracle.com/cve/CVE-2012-1137.html" source="CVE"/>
        <reference ref_id="CVE-2012-1139" ref_url="http://linux.oracle.com/cve/CVE-2012-1139.html" source="CVE"/>
        <reference ref_id="CVE-2012-1140" ref_url="http://linux.oracle.com/cve/CVE-2012-1140.html" source="CVE"/>
        <reference ref_id="CVE-2012-1141" ref_url="http://linux.oracle.com/cve/CVE-2012-1141.html" source="CVE"/>
        <reference ref_id="CVE-2012-1142" ref_url="http://linux.oracle.com/cve/CVE-2012-1142.html" source="CVE"/>
        <reference ref_id="CVE-2012-1143" ref_url="http://linux.oracle.com/cve/CVE-2012-1143.html" source="CVE"/>
        <reference ref_id="CVE-2012-1144" ref_url="http://linux.oracle.com/cve/CVE-2012-1144.html" source="CVE"/>
        <description>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:02.338-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:49.677-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:17.395-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23301 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:21.479-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:59.812-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:49:15.403-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:49:15.403-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:106066"/>
            <criterion comment="freetype is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:105949"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:105873"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:105789"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:105405"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:105970"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23300" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1037: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1037-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1037.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2143" ref_url="http://linux.oracle.com/cve/CVE-2012-2143.html" source="CVE"/>
        <reference ref_id="CVE-2012-2655" ref_url="http://linux.oracle.com/cve/CVE-2012-2655.html" source="CVE"/>
        <description>PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:14.623-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:49.474-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:17.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23300 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:22.536-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:59.638-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:48:29.398-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:48:29.398-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106430"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106614"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106004"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106076"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106262"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106358"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106571"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106201"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106579"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:106633"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:105640"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:105911"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106539"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106184"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106233"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106613"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106581"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106299"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106507"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106560"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106556"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:106211"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23298" version="57" class="patch">
      <metadata>
        <title>ELSA-2013:0125: wireshark security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2013:0125-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0125.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1958" ref_url="http://linux.oracle.com/cve/CVE-2011-1958.html" source="CVE"/>
        <reference ref_id="CVE-2011-1959" ref_url="http://linux.oracle.com/cve/CVE-2011-1959.html" source="CVE"/>
        <reference ref_id="CVE-2011-2175" ref_url="http://linux.oracle.com/cve/CVE-2011-2175.html" source="CVE"/>
        <reference ref_id="CVE-2011-2698" ref_url="http://linux.oracle.com/cve/CVE-2011-2698.html" source="CVE"/>
        <reference ref_id="CVE-2011-4102" ref_url="http://linux.oracle.com/cve/CVE-2011-4102.html" source="CVE"/>
        <reference ref_id="CVE-2012-0041" ref_url="http://linux.oracle.com/cve/CVE-2012-0041.html" source="CVE"/>
        <reference ref_id="CVE-2012-0042" ref_url="http://linux.oracle.com/cve/CVE-2012-0042.html" source="CVE"/>
        <reference ref_id="CVE-2012-0066" ref_url="http://linux.oracle.com/cve/CVE-2012-0066.html" source="CVE"/>
        <reference ref_id="CVE-2012-0067" ref_url="http://linux.oracle.com/cve/CVE-2012-0067.html" source="CVE"/>
        <reference ref_id="CVE-2012-4285" ref_url="http://linux.oracle.com/cve/CVE-2012-4285.html" source="CVE"/>
        <reference ref_id="CVE-2012-4289" ref_url="http://linux.oracle.com/cve/CVE-2012-4289.html" source="CVE"/>
        <reference ref_id="CVE-2012-4290" ref_url="http://linux.oracle.com/cve/CVE-2012-4290.html" source="CVE"/>
        <reference ref_id="CVE-2012-4291" ref_url="http://linux.oracle.com/cve/CVE-2012-4291.html" source="CVE"/>
        <description>The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:02.308-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:48.876-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:16.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23298 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:24.020-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:59.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-5.el5" test_ref="oval:org.mitre.oval:tst:106582"/>
          <criterion comment="wireshark is earlier than 0:1.0.15-5.el5" test_ref="oval:org.mitre.oval:tst:106112"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23296" version="41" class="patch">
      <metadata>
        <title>ELSA-2012:0730: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:0730-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-0730.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1711" ref_url="http://linux.oracle.com/cve/CVE-2012-1711.html" source="CVE"/>
        <reference ref_id="CVE-2012-1713" ref_url="http://linux.oracle.com/cve/CVE-2012-1713.html" source="CVE"/>
        <reference ref_id="CVE-2012-1716" ref_url="http://linux.oracle.com/cve/CVE-2012-1716.html" source="CVE"/>
        <reference ref_id="CVE-2012-1717" ref_url="http://linux.oracle.com/cve/CVE-2012-1717.html" source="CVE"/>
        <reference ref_id="CVE-2012-1718" ref_url="http://linux.oracle.com/cve/CVE-2012-1718.html" source="CVE"/>
        <reference ref_id="CVE-2012-1719" ref_url="http://linux.oracle.com/cve/CVE-2012-1719.html" source="CVE"/>
        <reference ref_id="CVE-2012-1723" ref_url="http://linux.oracle.com/cve/CVE-2012-1723.html" source="CVE"/>
        <reference ref_id="CVE-2012-1724" ref_url="http://linux.oracle.com/cve/CVE-2012-1724.html" source="CVE"/>
        <reference ref_id="CVE-2012-1725" ref_url="http://linux.oracle.com/cve/CVE-2012-1725.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:03.160-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:48.382-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:15.993-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23296 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:25.154-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:59.067-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:106127"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:106557"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:106567"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:106521"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.27.1.10.8.el5_8" test_ref="oval:org.mitre.oval:tst:106364"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23295" version="37" class="patch">
      <metadata>
        <title>ELSA-2012:0127: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2012:0127-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0127.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1849" ref_url="http://linux.oracle.com/cve/CVE-2010-1849.html" source="CVE"/>
        <reference ref_id="CVE-2012-0075" ref_url="http://linux.oracle.com/cve/CVE-2012-0075.html" source="CVE"/>
        <reference ref_id="CVE-2012-0087" ref_url="http://linux.oracle.com/cve/CVE-2012-0087.html" source="CVE"/>
        <reference ref_id="CVE-2012-0101" ref_url="http://linux.oracle.com/cve/CVE-2012-0101.html" source="CVE"/>
        <reference ref_id="CVE-2012-0102" ref_url="http://linux.oracle.com/cve/CVE-2012-0102.html" source="CVE"/>
        <reference ref_id="CVE-2012-0114" ref_url="http://linux.oracle.com/cve/CVE-2012-0114.html" source="CVE"/>
        <reference ref_id="CVE-2012-0484" ref_url="http://linux.oracle.com/cve/CVE-2012-0484.html" source="CVE"/>
        <reference ref_id="CVE-2012-0490" ref_url="http://linux.oracle.com/cve/CVE-2012-0490.html" source="CVE"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:56.210-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:48.179-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:15.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23295 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:25.289-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:58.847-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-server is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:104972"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105614"/>
          <criterion comment="mysql-test is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105464"/>
          <criterion comment="mysql is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105820"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105698"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23294" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0127: libvirt security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2013:0127-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0127.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2693" ref_url="http://linux.oracle.com/cve/CVE-2012-2693.html" source="CVE"/>
        <description>libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:56.985-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:48.118-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:15.532-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23294 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:21.343-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:58.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-python is earlier than 0:0.8.2-29.el5" test_ref="oval:org.mitre.oval:tst:107047"/>
          <criterion comment="libvirt is earlier than 0:0.8.2-29.el5" test_ref="oval:org.mitre.oval:tst:106895"/>
          <criterion comment="libvirt-devel is earlier than 0:0.8.2-29.el5" test_ref="oval:org.mitre.oval:tst:106920"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23293" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1212: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:1212-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1212.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2482" ref_url="http://linux.oracle.com/cve/CVE-2011-2482.html" source="CVE"/>
        <reference ref_id="CVE-2011-2491" ref_url="http://linux.oracle.com/cve/CVE-2011-2491.html" source="CVE"/>
        <reference ref_id="CVE-2011-2495" ref_url="http://linux.oracle.com/cve/CVE-2011-2495.html" source="CVE"/>
        <reference ref_id="CVE-2011-2517" ref_url="http://linux.oracle.com/cve/CVE-2011-2517.html" source="CVE"/>
        <reference ref_id="CVE-2011-2519" ref_url="http://linux.oracle.com/cve/CVE-2011-2519.html" source="CVE"/>
        <reference ref_id="CVE-2011-2901" ref_url="http://linux.oracle.com/cve/CVE-2011-2901.html" source="CVE"/>
        <description>Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:25.802-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:47.922-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:15.244-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23293 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:22.185-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:58.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105058"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105100"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105261"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105285"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105109"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105221"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:104349"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105150"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105012"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:104717"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:105311"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.3.1.el5" test_ref="oval:org.mitre.oval:tst:104572"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23292" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1815: icu security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>icu</product>
        </affected>
        <reference ref_id="ELSA-2011:1815-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1815.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4599" ref_url="http://linux.oracle.com/cve/CVE-2011-4599.html" source="CVE"/>
        <description>Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:34.435-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:47.852-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:15.126-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23292 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:22.675-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:58.411-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:46:49.652-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:46:49.652-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:105479"/>
            <criterion comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:105386"/>
            <criterion comment="libicu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:105478"/>
            <criterion comment="icu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:104645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libicu-devel is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:105567"/>
            <criterion comment="libicu-doc is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:105364"/>
            <criterion comment="libicu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:105569"/>
            <criterion comment="icu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:105583"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23289" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1136: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openoffice.org</product>
        </affected>
        <reference ref_id="ELSA-2012:1136-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1136.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2665" ref_url="http://linux.oracle.com/cve/CVE-2012-2665.html" source="CVE"/>
        <description>Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:12.844-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:47.481-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:14.620-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23289 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:23.241-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:57.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106730"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106719"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:105984"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106689"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106455"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106010"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:105891"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106551"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106478"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:105801"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106406"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:105944"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106251"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106530"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106035"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106754"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106624"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106661"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106464"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106657"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106736"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106712"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106417"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106763"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106779"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106337"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106748"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106546"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106344"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106591"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106584"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:105825"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106460"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106359"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106022"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106784"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106398"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106045"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106377"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106573"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106463"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106662"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106408"/>
          <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106636"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106747"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106702"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106593"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106776"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106741"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106412"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106167"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106757"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:105877"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106071"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106676"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106595"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106292"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106342"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106186"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106289"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106759"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106322"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106405"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106683"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106726"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106631"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106716"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106367"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106578"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106705"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106376"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106693"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106281"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106297"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106751"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106423"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106655"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.4" test_ref="oval:org.mitre.oval:tst:106442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23288" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1288: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:1288-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1288.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3102" ref_url="http://linux.oracle.com/cve/CVE-2011-3102.html" source="CVE"/>
        <reference ref_id="CVE-2012-2807" ref_url="http://linux.oracle.com/cve/CVE-2012-2807.html" source="CVE"/>
        <description>Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:46.114-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:47.376-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:14.419-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23288 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:23.624-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:57.727-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:45:57.526-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:45:57.526-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:106844"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:106506"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:106969"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:106293"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:106672"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:106724"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:105992"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23287" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0322: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:0322-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0322.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3563" ref_url="http://linux.oracle.com/cve/CVE-2011-3563.html" source="CVE"/>
        <reference ref_id="CVE-2011-3571" ref_url="http://linux.oracle.com/cve/CVE-2011-3571.html" source="CVE"/>
        <reference ref_id="CVE-2011-5035" ref_url="http://linux.oracle.com/cve/CVE-2011-5035.html" source="CVE"/>
        <reference ref_id="CVE-2012-0497" ref_url="http://linux.oracle.com/cve/CVE-2012-0497.html" source="CVE"/>
        <reference ref_id="CVE-2012-0501" ref_url="http://linux.oracle.com/cve/CVE-2012-0501.html" source="CVE"/>
        <reference ref_id="CVE-2012-0502" ref_url="http://linux.oracle.com/cve/CVE-2012-0502.html" source="CVE"/>
        <reference ref_id="CVE-2012-0503" ref_url="http://linux.oracle.com/cve/CVE-2012-0503.html" source="CVE"/>
        <reference ref_id="CVE-2012-0505" ref_url="http://linux.oracle.com/cve/CVE-2012-0505.html" source="CVE"/>
        <reference ref_id="CVE-2012-0506" ref_url="http://linux.oracle.com/cve/CVE-2012-0506.html" source="CVE"/>
        <reference ref_id="CVE-2012-0507" ref_url="http://linux.oracle.com/cve/CVE-2012-0507.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.	NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:01.936-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:47.152-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:13.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23287 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:21.716-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:57.427-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:105906"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:105808"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:105832"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:105809"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.25.1.10.6.el5_8" test_ref="oval:org.mitre.oval:tst:106005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23280" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1326: pango security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pango</product>
        </affected>
        <reference ref_id="ELSA-2011:1326-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1326.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3193" ref_url="http://linux.oracle.com/cve/CVE-2011-3193.html" source="CVE"/>
        <description>Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:29.216-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:46.191-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:12.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23280 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:20.484-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:56.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pango-devel is earlier than 0:1.14.9-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:105141"/>
          <criterion comment="pango is earlier than 0:1.14.9-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:105015"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23279" version="86" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1351: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1351-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1351.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1956" ref_url="http://linux.oracle.com/cve/CVE-2012-1956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3982" ref_url="http://linux.oracle.com/cve/CVE-2012-3982.html" source="CVE"/>
        <reference ref_id="CVE-2012-3986" ref_url="http://linux.oracle.com/cve/CVE-2012-3986.html" source="CVE"/>
        <reference ref_id="CVE-2012-3988" ref_url="http://linux.oracle.com/cve/CVE-2012-3988.html" source="CVE"/>
        <reference ref_id="CVE-2012-3990" ref_url="http://linux.oracle.com/cve/CVE-2012-3990.html" source="CVE"/>
        <reference ref_id="CVE-2012-3991" ref_url="http://linux.oracle.com/cve/CVE-2012-3991.html" source="CVE"/>
        <reference ref_id="CVE-2012-3992" ref_url="http://linux.oracle.com/cve/CVE-2012-3992.html" source="CVE"/>
        <reference ref_id="CVE-2012-3993" ref_url="http://linux.oracle.com/cve/CVE-2012-3993.html" source="CVE"/>
        <reference ref_id="CVE-2012-3994" ref_url="http://linux.oracle.com/cve/CVE-2012-3994.html" source="CVE"/>
        <reference ref_id="CVE-2012-3995" ref_url="http://linux.oracle.com/cve/CVE-2012-3995.html" source="CVE"/>
        <reference ref_id="CVE-2012-4179" ref_url="http://linux.oracle.com/cve/CVE-2012-4179.html" source="CVE"/>
        <reference ref_id="CVE-2012-4180" ref_url="http://linux.oracle.com/cve/CVE-2012-4180.html" source="CVE"/>
        <reference ref_id="CVE-2012-4181" ref_url="http://linux.oracle.com/cve/CVE-2012-4181.html" source="CVE"/>
        <reference ref_id="CVE-2012-4182" ref_url="http://linux.oracle.com/cve/CVE-2012-4182.html" source="CVE"/>
        <reference ref_id="CVE-2012-4183" ref_url="http://linux.oracle.com/cve/CVE-2012-4183.html" source="CVE"/>
        <reference ref_id="CVE-2012-4184" ref_url="http://linux.oracle.com/cve/CVE-2012-4184.html" source="CVE"/>
        <reference ref_id="CVE-2012-4185" ref_url="http://linux.oracle.com/cve/CVE-2012-4185.html" source="CVE"/>
        <reference ref_id="CVE-2012-4186" ref_url="http://linux.oracle.com/cve/CVE-2012-4186.html" source="CVE"/>
        <reference ref_id="CVE-2012-4187" ref_url="http://linux.oracle.com/cve/CVE-2012-4187.html" source="CVE"/>
        <reference ref_id="CVE-2012-4188" ref_url="http://linux.oracle.com/cve/CVE-2012-4188.html" source="CVE"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:37.821-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:45.751-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:11.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23279 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:21.007-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:55.751-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:45:08.937-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:45:08.937-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:106904"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:106481"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23278" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:1045: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:1045-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1045.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4153" ref_url="http://linux.oracle.com/cve/CVE-2011-4153.html" source="CVE"/>
        <reference ref_id="CVE-2012-0057" ref_url="http://linux.oracle.com/cve/CVE-2012-0057.html" source="CVE"/>
        <reference ref_id="CVE-2012-0789" ref_url="http://linux.oracle.com/cve/CVE-2012-0789.html" source="CVE"/>
        <reference ref_id="CVE-2012-1172" ref_url="http://linux.oracle.com/cve/CVE-2012-1172.html" source="CVE"/>
        <reference ref_id="CVE-2012-2336" ref_url="http://linux.oracle.com/cve/CVE-2012-2336.html" source="CVE"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:16.740-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:45.553-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:11.160-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23278 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:20.748-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:55.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-ncurses is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106649"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106435"/>
          <criterion comment="php is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106421"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106171"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106576"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106647"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106332"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106107"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106509"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106318"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106646"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:105946"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106523"/>
          <criterion comment="php-common is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106434"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106347"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106295"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106632"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:106640"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-39.el5_8" test_ref="oval:org.mitre.oval:tst:105890"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23277" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0422: postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postfix</product>
        </affected>
        <reference ref_id="ELSA-2011:0422-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0422.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-2937" ref_url="http://linux.oracle.com/cve/CVE-2008-2937.html" source="CVE"/>
        <reference ref_id="CVE-2011-0411" ref_url="http://linux.oracle.com/cve/CVE-2011-0411.html" source="CVE"/>
        <description>The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:03.753-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:45.438-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:11.023-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23277 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:25.045-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:55.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postfix-pflogsumm is earlier than 2:2.3.3-2.2.el5_6" test_ref="oval:org.mitre.oval:tst:104826"/>
          <criterion comment="postfix is earlier than 2:2.3.3-2.2.el5_6" test_ref="oval:org.mitre.oval:tst:104697"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23276" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1392: httpd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2011:1392-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1392.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3368" ref_url="http://linux.oracle.com/cve/CVE-2011-3368.html" source="CVE"/>
        <description>The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:33.369-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:45.365-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:10.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23276 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:26.184-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:55.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:105240"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:105194"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:104966"/>
          <criterion comment="httpd is earlier than 0:2.2.3-53.el5_7.3" test_ref="oval:org.mitre.oval:tst:105181"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23274" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1407: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1407-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1407.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4194" ref_url="http://linux.oracle.com/cve/CVE-2012-4194.html" source="CVE"/>
        <reference ref_id="CVE-2012-4195" ref_url="http://linux.oracle.com/cve/CVE-2012-4195.html" source="CVE"/>
        <reference ref_id="CVE-2012-4196" ref_url="http://linux.oracle.com/cve/CVE-2012-4196.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:38.349-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:45.031-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:10.600-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23274 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:25.695-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:55.027-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:44:37.332-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:44:37.332-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:106699"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:106966"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:106600"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:106881"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:106889"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:106259"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23273" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0311: ibutils security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ibutils</product>
        </affected>
        <reference ref_id="ELSA-2012:0311-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0311.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-3277" ref_url="http://linux.oracle.com/cve/CVE-2008-3277.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:07.674-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.941-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:10.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23273 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:26.012-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:54.932-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ibutils-devel is earlier than 0:1.2-11.2.el5" test_ref="oval:org.mitre.oval:tst:105895"/>
          <criterion comment="ibutils is earlier than 0:1.2-11.2.el5" test_ref="oval:org.mitre.oval:tst:105227"/>
          <criterion comment="ibutils-libs is earlier than 0:1.2-11.2.el5" test_ref="oval:org.mitre.oval:tst:105441"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23272" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1444: nss security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2011:1444-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1444.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.
It was found that the Malaysia-based Digicert Sdn. Bhd. subordinate
Certificate Authority (CA) issued HTTPS certificates with weak keys. This
update renders any HTTPS certificates signed by that CA as untrusted. This
covers all uses of the certificates, including SSL, S/MIME, and code
signing. Note: Digicert Sdn. Bhd. is not the same company as found at
digicert.com. (BZ#751366)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
This update also fixes the following bug on Oracle Linux 5.x:
* When using mod_nss with the Apache HTTP Server, a bug in NSS on Red Hat
Enterprise Linux 5 resulted in file descriptors leaking each time the
Apache HTTP Server was restarted with the "service httpd reload" command.
This could have prevented the Apache HTTP Server from functioning properly
if all available file descriptors were consumed. (BZ#743508)
For Red Hat Enterprise Linux 6, these updated packages upgrade NSS to
version 3.12.10. As well, they upgrade NSPR (Netscape Portable Runtime) to
version 4.8.8 and nss-util to version 3.12.10 on Red Hat
Enterprise Linux 6, as required by the NSS update. (BZ#735972, BZ#736272,
BZ#735973)
All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect. In addition, on Red Hat
Enterprise Linux 6, applications using NSPR and nss-util must also be
restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:54.014-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.875-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:10.404-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23272 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:26.397-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:54.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:109396"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:109552"/>
            <criterion comment="nss is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:109492"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:109424"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:109132"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:108565"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:108973"/>
            <criterion comment="nss is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:108884"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:108865"/>
            <criterion comment="nspr is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:109048"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:109233"/>
            <criterion comment="nss-util is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:109289"/>
            <criterion comment="nss-util-devel is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:109354"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23271" version="57" class="patch">
      <metadata>
        <title>ELSA-2011:0887: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0887-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0887.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0083" ref_url="http://linux.oracle.com/cve/CVE-2011-0083.html" source="CVE"/>
        <reference ref_id="CVE-2011-0085" ref_url="http://linux.oracle.com/cve/CVE-2011-0085.html" source="CVE"/>
        <reference ref_id="CVE-2011-2362" ref_url="http://linux.oracle.com/cve/CVE-2011-2362.html" source="CVE"/>
        <reference ref_id="CVE-2011-2363" ref_url="http://linux.oracle.com/cve/CVE-2011-2363.html" source="CVE"/>
        <reference ref_id="CVE-2011-2364" ref_url="http://linux.oracle.com/cve/CVE-2011-2364.html" source="CVE"/>
        <reference ref_id="CVE-2011-2365" ref_url="http://linux.oracle.com/cve/CVE-2011-2365.html" source="CVE"/>
        <reference ref_id="CVE-2011-2371" ref_url="http://linux.oracle.com/cve/CVE-2011-2371.html" source="CVE"/>
        <reference ref_id="CVE-2011-2373" ref_url="http://linux.oracle.com/cve/CVE-2011-2373.html" source="CVE"/>
        <reference ref_id="CVE-2011-2374" ref_url="http://linux.oracle.com/cve/CVE-2011-2374.html" source="CVE"/>
        <reference ref_id="CVE-2011-2375" ref_url="http://linux.oracle.com/cve/CVE-2011-2375.html" source="CVE"/>
        <reference ref_id="CVE-2011-2376" ref_url="http://linux.oracle.com/cve/CVE-2011-2376.html" source="CVE"/>
        <reference ref_id="CVE-2011-2377" ref_url="http://linux.oracle.com/cve/CVE-2011-2377.html" source="CVE"/>
        <reference ref_id="CVE-2011-2605" ref_url="http://linux.oracle.com/cve/CVE-2011-2605.html" source="CVE"/>
        <description>CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:18.576-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.611-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:09.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23271 - optimisation of Oracle Linux content" date="2014-05-05T17:44:00.981-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:46:25.895-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:54.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-18.el5_6" test_ref="oval:org.mitre.oval:tst:105040"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23270" version="49" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1445: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1445-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1445.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2445" ref_url="http://linux.oracle.com/cve/CVE-2011-2445.html" source="CVE"/>
        <reference ref_id="CVE-2011-2450" ref_url="http://linux.oracle.com/cve/CVE-2011-2450.html" source="CVE"/>
        <reference ref_id="CVE-2011-2451" ref_url="http://linux.oracle.com/cve/CVE-2011-2451.html" source="CVE"/>
        <reference ref_id="CVE-2011-2452" ref_url="http://linux.oracle.com/cve/CVE-2011-2452.html" source="CVE"/>
        <reference ref_id="CVE-2011-2453" ref_url="http://linux.oracle.com/cve/CVE-2011-2453.html" source="CVE"/>
        <reference ref_id="CVE-2011-2454" ref_url="http://linux.oracle.com/cve/CVE-2011-2454.html" source="CVE"/>
        <reference ref_id="CVE-2011-2455" ref_url="http://linux.oracle.com/cve/CVE-2011-2455.html" source="CVE"/>
        <reference ref_id="CVE-2011-2456" ref_url="http://linux.oracle.com/cve/CVE-2011-2456.html" source="CVE"/>
        <reference ref_id="CVE-2011-2457" ref_url="http://linux.oracle.com/cve/CVE-2011-2457.html" source="CVE"/>
        <reference ref_id="CVE-2011-2459" ref_url="http://linux.oracle.com/cve/CVE-2011-2459.html" source="CVE"/>
        <reference ref_id="CVE-2011-2460" ref_url="http://linux.oracle.com/cve/CVE-2011-2460.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:38.835-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.363-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:09.211-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23270 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:32.676-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:43:54.418-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:43:54.418-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el5" test_ref="oval:org.mitre.oval:tst:105241"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el6" test_ref="oval:org.mitre.oval:tst:105171"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23269" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0309: sudo security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2012:0309-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0309.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0010" ref_url="http://linux.oracle.com/cve/CVE-2011-0010.html" source="CVE"/>
        <description>check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:08.101-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.298-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:09.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23269 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:03.240-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:54.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-13.el5" test_ref="oval:org.mitre.oval:tst:105197"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23268" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:0838: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2011:0838-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0838.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-1570" ref_url="http://linux.oracle.com/cve/CVE-2009-1570.html" source="CVE"/>
        <reference ref_id="CVE-2010-4540" ref_url="http://linux.oracle.com/cve/CVE-2010-4540.html" source="CVE"/>
        <reference ref_id="CVE-2010-4541" ref_url="http://linux.oracle.com/cve/CVE-2010-4541.html" source="CVE"/>
        <reference ref_id="CVE-2010-4542" ref_url="http://linux.oracle.com/cve/CVE-2010-4542.html" source="CVE"/>
        <reference ref_id="CVE-2010-4543" ref_url="http://linux.oracle.com/cve/CVE-2010-4543.html" source="CVE"/>
        <reference ref_id="CVE-2011-1178" ref_url="http://linux.oracle.com/cve/CVE-2011-1178.html" source="CVE"/>
        <description>Multiple integer overflows in the load_image function in file-pcx.c in the Personal Computer Exchange (PCX) plugin in GIMP 2.6.x and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PCX image that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:24.418-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.151-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:08.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23268 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.446-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:54.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gimp-libs is earlier than 2:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:104946"/>
          <criterion comment="gimp-devel is earlier than 2:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:104132"/>
          <criterion comment="gimp is earlier than 2:2.2.13-2.0.7.el5_6.2" test_ref="oval:org.mitre.oval:tst:105056"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23267" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0376: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus</product>
        </affected>
        <reference ref_id="ELSA-2011:0376-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0376.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4352" ref_url="http://linux.oracle.com/cve/CVE-2010-4352.html" source="CVE"/>
        <description>Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:17.481-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.073-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:08.658-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23267 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:58.209-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:54.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:104770"/>
            <criterion comment="dbus is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:104810"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:104759"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:103947"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:104930"/>
            <criterion comment="dbus is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:104937"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:103955"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:104112"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:104872"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23266" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0120: quota security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>quota</product>
        </affected>
        <reference ref_id="ELSA-2013:0120-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0120.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3417" ref_url="http://linux.oracle.com/cve/CVE-2012-3417.html" source="CVE"/>
        <description>The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:01.272-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:44.016-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:08.559-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23266 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.069-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:53.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="quota is earlier than 1:3.13-8.el5" test_ref="oval:org.mitre.oval:tst:107007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23265" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1327: freeradius2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>freeradius2</product>
        </affected>
        <reference ref_id="ELSA-2012:1327-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1327.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3547" ref_url="http://linux.oracle.com/cve/CVE-2012-3547.html" source="CVE"/>
        <description>Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:45.190-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:43.937-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:08.433-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23265 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.352-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:53.865-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="freeradius2-python is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106766"/>
          <criterion comment="freeradius2-unixODBC is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:107010"/>
          <criterion comment="freeradius2-krb5 is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106143"/>
          <criterion comment="freeradius2 is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106271"/>
          <criterion comment="freeradius2-perl is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106528"/>
          <criterion comment="freeradius2-ldap is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106999"/>
          <criterion comment="freeradius2-mysql is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106029"/>
          <criterion comment="freeradius2-postgresql is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106888"/>
          <criterion comment="freeradius2-utils is earlier than 0:2.1.12-4.el5_8" test_ref="oval:org.mitre.oval:tst:106951"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23264" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1422: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2011:1422-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1422.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4073" ref_url="http://linux.oracle.com/cve/CVE-2011-4073.html" source="CVE"/>
        <description>Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:38.710-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:43.871-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:08.329-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23264 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:57.942-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:53.750-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:43:23.854-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:43:23.854-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:105336"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:105211"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:105373"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:105428"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23263" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0321: cvs security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>cvs</product>
        </affected>
        <reference ref_id="ELSA-2012:0321-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0321.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0804" ref_url="http://linux.oracle.com/cve/CVE-2012-0804.html" source="CVE"/>
        <description>Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:58.062-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:43.809-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:08.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23263 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.602-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:53.642-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:42:46.106-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:42:46.106-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cvs-inetd is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:105839"/>
            <criterion comment="cvs is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:105838"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="cvs is earlier than 0:1.11.23-11.el6_2.1" test_ref="oval:org.mitre.oval:tst:105342"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23262" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0998: kvm security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2010:0998-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0998.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3881" ref_url="http://linux.oracle.com/cve/CVE-2010-3881.html" source="CVE"/>
        <description>arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:16.955-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:43.740-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:08.123-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23262 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.594-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:53.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:104500"/>
          <criterion comment="kvm is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:104518"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:104520"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.el5_5.30" test_ref="oval:org.mitre.oval:tst:104172"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23261" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0169: java-1.5.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0169-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0169.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <description>Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the color profile parser that allows remote attackers to execute arbitrary code via a crafted Tag structure in a color profile.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:04.527-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:43.612-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:07.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23261 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:01.357-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:53.331-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:42:11.213-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:42:11.213-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104601"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104478"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104556"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104507"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104669"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104628"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104654"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104483"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:103873"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:104420"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:103979"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:103723"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:104663"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:104662"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:104579"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23260" version="110" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1505: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1505-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1505.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:31.163-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:42.994-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:06.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23260 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:01.190-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:52.709-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:40:54.360-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:40:54.360-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:107819"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:107827"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:107565"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:107715"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:107570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:107849"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:107583"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:107503"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:107725"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:107782"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23258" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1174: kernel security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1174-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1174.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2313" ref_url="http://linux.oracle.com/cve/CVE-2012-2313.html" source="CVE"/>
        <description>The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:02.041-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:42.858-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:06.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23258 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:01.794-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:52.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106046"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106017"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106323"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106585"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106788"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:105901"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106118"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106619"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106511"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106735"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:106660"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.13.1.el5" test_ref="oval:org.mitre.oval:tst:105833"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23256" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1164: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1164-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1164.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0084" ref_url="http://linux.oracle.com/cve/CVE-2011-0084.html" source="CVE"/>
        <reference ref_id="CVE-2011-2378" ref_url="http://linux.oracle.com/cve/CVE-2011-2378.html" source="CVE"/>
        <reference ref_id="CVE-2011-2981" ref_url="http://linux.oracle.com/cve/CVE-2011-2981.html" source="CVE"/>
        <reference ref_id="CVE-2011-2982" ref_url="http://linux.oracle.com/cve/CVE-2011-2982.html" source="CVE"/>
        <reference ref_id="CVE-2011-2983" ref_url="http://linux.oracle.com/cve/CVE-2011-2983.html" source="CVE"/>
        <reference ref_id="CVE-2011-2984" ref_url="http://linux.oracle.com/cve/CVE-2011-2984.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:25.408-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:42.450-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:06.157-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23256 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:01.681-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:52.140-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:39:56.877-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:39:56.877-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:105187"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:105166"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el5" test_ref="oval:org.mitre.oval:tst:104798"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:105068"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:105306"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:105179"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23255" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0307: mailman security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mailman</product>
        </affected>
        <reference ref_id="ELSA-2011:0307-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0307.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-0564" ref_url="http://linux.oracle.com/cve/CVE-2008-0564.html" source="CVE"/>
        <reference ref_id="CVE-2010-3089" ref_url="http://linux.oracle.com/cve/CVE-2010-3089.html" source="CVE"/>
        <reference ref_id="CVE-2011-0707" ref_url="http://linux.oracle.com/cve/CVE-2011-0707.html" source="CVE"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:01.478-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:42.338-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:05.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23255 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.762-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:52.006-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="mailman is earlier than 3:2.1.9-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:104911"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23254" version="50" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010:0966: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2010:0966-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0966.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3766" ref_url="http://linux.oracle.com/cve/CVE-2010-3766.html" source="CVE"/>
        <reference ref_id="CVE-2010-3767" ref_url="http://linux.oracle.com/cve/CVE-2010-3767.html" source="CVE"/>
        <reference ref_id="CVE-2010-3768" ref_url="http://linux.oracle.com/cve/CVE-2010-3768.html" source="CVE"/>
        <reference ref_id="CVE-2010-3770" ref_url="http://linux.oracle.com/cve/CVE-2010-3770.html" source="CVE"/>
        <reference ref_id="CVE-2010-3771" ref_url="http://linux.oracle.com/cve/CVE-2010-3771.html" source="CVE"/>
        <reference ref_id="CVE-2010-3772" ref_url="http://linux.oracle.com/cve/CVE-2010-3772.html" source="CVE"/>
        <reference ref_id="CVE-2010-3773" ref_url="http://linux.oracle.com/cve/CVE-2010-3773.html" source="CVE"/>
        <reference ref_id="CVE-2010-3774" ref_url="http://linux.oracle.com/cve/CVE-2010-3774.html" source="CVE"/>
        <reference ref_id="CVE-2010-3775" ref_url="http://linux.oracle.com/cve/CVE-2010-3775.html" source="CVE"/>
        <reference ref_id="CVE-2010-3776" ref_url="http://linux.oracle.com/cve/CVE-2010-3776.html" source="CVE"/>
        <reference ref_id="CVE-2010-3777" ref_url="http://linux.oracle.com/cve/CVE-2010-3777.html" source="CVE"/>
        <description>Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:29.929-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:42.075-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:05.588-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23254 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.405-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:51.770-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:39:11.373-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:39:11.373-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:103832"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:104569"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el5" test_ref="oval:org.mitre.oval:tst:104526"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:104597"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:104439"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el6_0" test_ref="oval:org.mitre.oval:tst:104413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23253" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0434: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0434-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0434.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0773" ref_url="http://linux.oracle.com/cve/CVE-2012-0773.html" source="CVE"/>
        <description>The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:00.830-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:42.004-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:05.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23253 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:03.094-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:51.679-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:38:26.802-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:38:26.802-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el5" test_ref="oval:org.mitre.oval:tst:105976"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el6" test_ref="oval:org.mitre.oval:tst:105072"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23252" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0678: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:0678-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0678.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0866" ref_url="http://linux.oracle.com/cve/CVE-2012-0866.html" source="CVE"/>
        <reference ref_id="CVE-2012-0867" ref_url="http://linux.oracle.com/cve/CVE-2012-0867.html" source="CVE"/>
        <reference ref_id="CVE-2012-0868" ref_url="http://linux.oracle.com/cve/CVE-2012-0868.html" source="CVE"/>
        <description>CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:04.443-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:41.862-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:05.256-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23252 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:59.741-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:51.482-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:37:53.901-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:37:53.901-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106207"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106040"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106199"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106291"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:105998"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:105994"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:105931"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:105675"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106185"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106197"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106225"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:105916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:105765"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:106113"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:105900"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:106278"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:105733"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:106246"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:106243"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:106190"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:106172"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:106006"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23251" version="102" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1210: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1210-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1210.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1970" ref_url="http://linux.oracle.com/cve/CVE-2012-1970.html" source="CVE"/>
        <reference ref_id="CVE-2012-1972" ref_url="http://linux.oracle.com/cve/CVE-2012-1972.html" source="CVE"/>
        <reference ref_id="CVE-2012-1973" ref_url="http://linux.oracle.com/cve/CVE-2012-1973.html" source="CVE"/>
        <reference ref_id="CVE-2012-1974" ref_url="http://linux.oracle.com/cve/CVE-2012-1974.html" source="CVE"/>
        <reference ref_id="CVE-2012-1975" ref_url="http://linux.oracle.com/cve/CVE-2012-1975.html" source="CVE"/>
        <reference ref_id="CVE-2012-1976" ref_url="http://linux.oracle.com/cve/CVE-2012-1976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3956" ref_url="http://linux.oracle.com/cve/CVE-2012-3956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3957" ref_url="http://linux.oracle.com/cve/CVE-2012-3957.html" source="CVE"/>
        <reference ref_id="CVE-2012-3958" ref_url="http://linux.oracle.com/cve/CVE-2012-3958.html" source="CVE"/>
        <reference ref_id="CVE-2012-3959" ref_url="http://linux.oracle.com/cve/CVE-2012-3959.html" source="CVE"/>
        <reference ref_id="CVE-2012-3960" ref_url="http://linux.oracle.com/cve/CVE-2012-3960.html" source="CVE"/>
        <reference ref_id="CVE-2012-3961" ref_url="http://linux.oracle.com/cve/CVE-2012-3961.html" source="CVE"/>
        <reference ref_id="CVE-2012-3962" ref_url="http://linux.oracle.com/cve/CVE-2012-3962.html" source="CVE"/>
        <reference ref_id="CVE-2012-3963" ref_url="http://linux.oracle.com/cve/CVE-2012-3963.html" source="CVE"/>
        <reference ref_id="CVE-2012-3964" ref_url="http://linux.oracle.com/cve/CVE-2012-3964.html" source="CVE"/>
        <reference ref_id="CVE-2012-3966" ref_url="http://linux.oracle.com/cve/CVE-2012-3966.html" source="CVE"/>
        <reference ref_id="CVE-2012-3967" ref_url="http://linux.oracle.com/cve/CVE-2012-3967.html" source="CVE"/>
        <reference ref_id="CVE-2012-3968" ref_url="http://linux.oracle.com/cve/CVE-2012-3968.html" source="CVE"/>
        <reference ref_id="CVE-2012-3969" ref_url="http://linux.oracle.com/cve/CVE-2012-3969.html" source="CVE"/>
        <reference ref_id="CVE-2012-3970" ref_url="http://linux.oracle.com/cve/CVE-2012-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-3972" ref_url="http://linux.oracle.com/cve/CVE-2012-3972.html" source="CVE"/>
        <reference ref_id="CVE-2012-3976" ref_url="http://linux.oracle.com/cve/CVE-2012-3976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3978" ref_url="http://linux.oracle.com/cve/CVE-2012-3978.html" source="CVE"/>
        <reference ref_id="CVE-2012-3980" ref_url="http://linux.oracle.com/cve/CVE-2012-3980.html" source="CVE"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:34.731-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:41.342-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:05.086-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23251 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:59.899-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:51.303-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:36:17.166-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:36:17.166-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:106708"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:106630"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:106498"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:106746"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:106805"/>
            <criterion comment="firefox is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:106610"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23250" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1149: sudo security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2012:1149-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1149.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3440" ref_url="http://linux.oracle.com/cve/CVE-2012-3440.html" source="CVE"/>
        <description>A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:13.274-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:41.278-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:04.988-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23250 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.527-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:51.209-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8.2" test_ref="oval:org.mitre.oval:tst:106508"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23248" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1242: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2011:1242-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1242.html" source="VENDOR"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Firefox; however, affected certificates issued
after this date cannot be re-enabled or used. (BZ#734316)
All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:39.301-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:41.055-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:04.581-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23248 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:03.005-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:50.931-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:35:33.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:35:33.988-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:104982"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:104516"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:104428"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:105324"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23246" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0844: apr security update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference ref_id="ELSA-2011:0844-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0844.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1928" ref_url="http://linux.oracle.com/cve/CVE-2011-1928.html" source="CVE"/>
        <description>The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used.  NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:19.684-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:40.846-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:02.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23246 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.683-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:50.662-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:34:51.044-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:34:51.044-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:105060"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:104802"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:104203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:104414"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:104635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23245" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0935: java-1.4.2-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0935-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0935.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1321" ref_url="http://linux.oracle.com/cve/CVE-2010-1321.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:31.755-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:40.756-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:02.612-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23245 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.848-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:50.528-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104552"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104613"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104092"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104521"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104455"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104111"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.7-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104451"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23244" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:0107: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0107-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0107.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3638" ref_url="http://linux.oracle.com/cve/CVE-2011-3638.html" source="CVE"/>
        <reference ref_id="CVE-2011-4086" ref_url="http://linux.oracle.com/cve/CVE-2011-4086.html" source="CVE"/>
        <reference ref_id="CVE-2011-4127" ref_url="http://linux.oracle.com/cve/CVE-2011-4127.html" source="CVE"/>
        <reference ref_id="CVE-2012-0028" ref_url="http://linux.oracle.com/cve/CVE-2012-0028.html" source="CVE"/>
        <reference ref_id="CVE-2012-0207" ref_url="http://linux.oracle.com/cve/CVE-2012-0207.html" source="CVE"/>
        <description>The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:00.680-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:40.597-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:02.311-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23244 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.245-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:50.326-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105387"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105692"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105858"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105843"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105627"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105774"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105603"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105787"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105775"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105656"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105725"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.18.1.el5" test_ref="oval:org.mitre.oval:tst:105798"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23243" version="94" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0247: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0247-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0247.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0429" ref_url="http://linux.oracle.com/cve/CVE-2013-0429.html" source="CVE"/>
        <reference ref_id="CVE-2013-0431" ref_url="http://linux.oracle.com/cve/CVE-2013-0431.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0435" ref_url="http://linux.oracle.com/cve/CVE-2013-0435.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0441" ref_url="http://linux.oracle.com/cve/CVE-2013-0441.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0444" ref_url="http://linux.oracle.com/cve/CVE-2013-0444.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-1475" ref_url="http://linux.oracle.com/cve/CVE-2013-1475.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.	 NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:55.779-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:40.103-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:01.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23243 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:01.938-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:50.107-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:34:09.287-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:34:09.287-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:107127"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:107009"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:106963"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:106235"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:106832"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:106934"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:106209"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:107095"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:107085"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:107036"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23242" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0683: axis security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>axis</product>
        </affected>
        <reference ref_id="ELSA-2013:0683-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0683.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5784" ref_url="http://linux.oracle.com/cve/CVE-2012-5784.html" source="CVE"/>
        <description>Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:47.800-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:40.002-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:01.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23242 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.147-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:49.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="axis-javadoc is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:107067"/>
          <criterion comment="axis-manual is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:107099"/>
          <criterion comment="axis is earlier than 0:1.2.1-2jpp.7.el5_9" test_ref="oval:org.mitre.oval:tst:107382"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23240" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0313: samba security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2012:0313-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0313.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0926" ref_url="http://linux.oracle.com/cve/CVE-2010-0926.html" source="CVE"/>
        <description>The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:08.660-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.808-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:01.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23240 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.195-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:49.800-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:105871"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:105961"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:105822"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:105935"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:105002"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.37.el5" test_ref="oval:org.mitre.oval:tst:105836"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23239" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1851: krb5 security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2011:1851-02" ref_url="http://linux.oracle.com/errata/ELSA-2011-1851.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4862" ref_url="http://linux.oracle.com/cve/CVE-2011-4862.html" source="CVE"/>
        <description>Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:23.271-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.735-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:00.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23239 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.679-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:49.707-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:105507"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:105695"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:105651"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:105212"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:105539"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-63.el5_7" test_ref="oval:org.mitre.oval:tst:105168"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23238" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0312: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0312-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0312.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0051" ref_url="http://linux.oracle.com/cve/CVE-2011-0051.html" source="CVE"/>
        <reference ref_id="CVE-2011-0053" ref_url="http://linux.oracle.com/cve/CVE-2011-0053.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:11.370-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.654-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:00.840-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23238 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:02.929-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:49.605-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-14.el5_6" test_ref="oval:org.mitre.oval:tst:104706"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23237" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1452: vino security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference ref_id="ELSA-2013:1452-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1452.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5745" ref_url="http://linux.oracle.com/cve/CVE-2013-5745.html" source="CVE"/>
        <description>The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:37.385-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.593-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:00.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23237 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:03.312-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:49.433-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:33:14.202-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:33:14.202-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="vino is earlier than 0:2.28.1-9.el6_4" test_ref="oval:org.mitre.oval:tst:107644"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="vino is earlier than 0:2.13.5-10.el5_10" test_ref="oval:org.mitre.oval:tst:107587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23236" version="54" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0516: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0516-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0516.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3062" ref_url="http://linux.oracle.com/cve/CVE-2011-3062.html" source="CVE"/>
        <reference ref_id="CVE-2012-0467" ref_url="http://linux.oracle.com/cve/CVE-2012-0467.html" source="CVE"/>
        <reference ref_id="CVE-2012-0468" ref_url="http://linux.oracle.com/cve/CVE-2012-0468.html" source="CVE"/>
        <reference ref_id="CVE-2012-0469" ref_url="http://linux.oracle.com/cve/CVE-2012-0469.html" source="CVE"/>
        <reference ref_id="CVE-2012-0470" ref_url="http://linux.oracle.com/cve/CVE-2012-0470.html" source="CVE"/>
        <reference ref_id="CVE-2012-0471" ref_url="http://linux.oracle.com/cve/CVE-2012-0471.html" source="CVE"/>
        <reference ref_id="CVE-2012-0472" ref_url="http://linux.oracle.com/cve/CVE-2012-0472.html" source="CVE"/>
        <reference ref_id="CVE-2012-0473" ref_url="http://linux.oracle.com/cve/CVE-2012-0473.html" source="CVE"/>
        <reference ref_id="CVE-2012-0474" ref_url="http://linux.oracle.com/cve/CVE-2012-0474.html" source="CVE"/>
        <reference ref_id="CVE-2012-0477" ref_url="http://linux.oracle.com/cve/CVE-2012-0477.html" source="CVE"/>
        <reference ref_id="CVE-2012-0478" ref_url="http://linux.oracle.com/cve/CVE-2012-0478.html" source="CVE"/>
        <reference ref_id="CVE-2012-0479" ref_url="http://linux.oracle.com/cve/CVE-2012-0479.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:00.132-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.352-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:00.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23236 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:58.938-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:49.068-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:32:42.603-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:32:42.603-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:105934"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:105465"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23235" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0143: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0143-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0143.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3026" ref_url="http://linux.oracle.com/cve/CVE-2011-3026.html" source="CVE"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:04.864-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.286-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:00.079-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23235 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:59.482-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:48.928-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:32:11.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:32:11.799-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:105592"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:105440"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:105224"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:104935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23234" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0717: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference ref_id="ELSA-2012:0717-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-0717.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1033" ref_url="http://linux.oracle.com/cve/CVE-2012-1033.html" source="CVE"/>
        <reference ref_id="CVE-2012-1667" ref_url="http://linux.oracle.com/cve/CVE-2012-1667.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:21:56.531-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.203-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:59.899-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23234 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.292-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:48.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:106193"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:106370"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:106549"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:106544"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.1" test_ref="oval:org.mitre.oval:tst:106547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23233" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0310: nfs-utils security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nfs-utils</product>
        </affected>
        <reference ref_id="ELSA-2012:0310-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0310.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1749" ref_url="http://linux.oracle.com/cve/CVE-2011-1749.html" source="CVE"/>
        <description>The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:06.642-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:39.143-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:59.793-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23233 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.921-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:48.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="nfs-utils is earlier than 1:1.0.9-60.el5" test_ref="oval:org.mitre.oval:tst:105568"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23232" version="61" class="patch">
      <metadata>
        <title>ELSA-2011:0004: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0004-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0004.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3432" ref_url="http://linux.oracle.com/cve/CVE-2010-3432.html" source="CVE"/>
        <reference ref_id="CVE-2010-3442" ref_url="http://linux.oracle.com/cve/CVE-2010-3442.html" source="CVE"/>
        <reference ref_id="CVE-2010-3699" ref_url="http://linux.oracle.com/cve/CVE-2010-3699.html" source="CVE"/>
        <reference ref_id="CVE-2010-3858" ref_url="http://linux.oracle.com/cve/CVE-2010-3858.html" source="CVE"/>
        <reference ref_id="CVE-2010-3859" ref_url="http://linux.oracle.com/cve/CVE-2010-3859.html" source="CVE"/>
        <reference ref_id="CVE-2010-3865" ref_url="http://linux.oracle.com/cve/CVE-2010-3865.html" source="CVE"/>
        <reference ref_id="CVE-2010-3876" ref_url="http://linux.oracle.com/cve/CVE-2010-3876.html" source="CVE"/>
        <reference ref_id="CVE-2010-3880" ref_url="http://linux.oracle.com/cve/CVE-2010-3880.html" source="CVE"/>
        <reference ref_id="CVE-2010-4083" ref_url="http://linux.oracle.com/cve/CVE-2010-4083.html" source="CVE"/>
        <reference ref_id="CVE-2010-4157" ref_url="http://linux.oracle.com/cve/CVE-2010-4157.html" source="CVE"/>
        <reference ref_id="CVE-2010-4161" ref_url="http://linux.oracle.com/cve/CVE-2010-4161.html" source="CVE"/>
        <reference ref_id="CVE-2010-4242" ref_url="http://linux.oracle.com/cve/CVE-2010-4242.html" source="CVE"/>
        <reference ref_id="CVE-2010-4247" ref_url="http://linux.oracle.com/cve/CVE-2010-4247.html" source="CVE"/>
        <reference ref_id="CVE-2010-4248" ref_url="http://linux.oracle.com/cve/CVE-2010-4248.html" source="CVE"/>
        <description>Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix-cpu-timers.c, and the selection of a new thread group leader in the de_thread function in fs/exec.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:16.849-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:38.848-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:59.135-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23232 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:59.364-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:48.277-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104359"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104252"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104564"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104384"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104622"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104573"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104370"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104328"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104547"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104303"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104391"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.32.1.el5" test_ref="oval:org.mitre.oval:tst:104525"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23231" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1797: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>perl</product>
        </affected>
        <reference ref_id="ELSA-2011:1797-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1797.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2761" ref_url="http://linux.oracle.com/cve/CVE-2010-2761.html" source="CVE"/>
        <reference ref_id="CVE-2010-4410" ref_url="http://linux.oracle.com/cve/CVE-2010-4410.html" source="CVE"/>
        <reference ref_id="CVE-2011-3597" ref_url="http://linux.oracle.com/cve/CVE-2011-3597.html" source="CVE"/>
        <description>Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:32.001-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:38.758-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:58.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23231 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:59.563-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:48.152-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="perl-suidperl is earlier than 4:5.8.8-32.el5_7.6" test_ref="oval:org.mitre.oval:tst:105575"/>
          <criterion comment="perl is earlier than 4:5.8.8-32.el5_7.6" test_ref="oval:org.mitre.oval:tst:104716"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23230" version="98" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1211: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1211-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1211.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1970" ref_url="http://linux.oracle.com/cve/CVE-2012-1970.html" source="CVE"/>
        <reference ref_id="CVE-2012-1972" ref_url="http://linux.oracle.com/cve/CVE-2012-1972.html" source="CVE"/>
        <reference ref_id="CVE-2012-1973" ref_url="http://linux.oracle.com/cve/CVE-2012-1973.html" source="CVE"/>
        <reference ref_id="CVE-2012-1974" ref_url="http://linux.oracle.com/cve/CVE-2012-1974.html" source="CVE"/>
        <reference ref_id="CVE-2012-1975" ref_url="http://linux.oracle.com/cve/CVE-2012-1975.html" source="CVE"/>
        <reference ref_id="CVE-2012-1976" ref_url="http://linux.oracle.com/cve/CVE-2012-1976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3956" ref_url="http://linux.oracle.com/cve/CVE-2012-3956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3957" ref_url="http://linux.oracle.com/cve/CVE-2012-3957.html" source="CVE"/>
        <reference ref_id="CVE-2012-3958" ref_url="http://linux.oracle.com/cve/CVE-2012-3958.html" source="CVE"/>
        <reference ref_id="CVE-2012-3959" ref_url="http://linux.oracle.com/cve/CVE-2012-3959.html" source="CVE"/>
        <reference ref_id="CVE-2012-3960" ref_url="http://linux.oracle.com/cve/CVE-2012-3960.html" source="CVE"/>
        <reference ref_id="CVE-2012-3961" ref_url="http://linux.oracle.com/cve/CVE-2012-3961.html" source="CVE"/>
        <reference ref_id="CVE-2012-3962" ref_url="http://linux.oracle.com/cve/CVE-2012-3962.html" source="CVE"/>
        <reference ref_id="CVE-2012-3963" ref_url="http://linux.oracle.com/cve/CVE-2012-3963.html" source="CVE"/>
        <reference ref_id="CVE-2012-3964" ref_url="http://linux.oracle.com/cve/CVE-2012-3964.html" source="CVE"/>
        <reference ref_id="CVE-2012-3966" ref_url="http://linux.oracle.com/cve/CVE-2012-3966.html" source="CVE"/>
        <reference ref_id="CVE-2012-3967" ref_url="http://linux.oracle.com/cve/CVE-2012-3967.html" source="CVE"/>
        <reference ref_id="CVE-2012-3968" ref_url="http://linux.oracle.com/cve/CVE-2012-3968.html" source="CVE"/>
        <reference ref_id="CVE-2012-3969" ref_url="http://linux.oracle.com/cve/CVE-2012-3969.html" source="CVE"/>
        <reference ref_id="CVE-2012-3970" ref_url="http://linux.oracle.com/cve/CVE-2012-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-3972" ref_url="http://linux.oracle.com/cve/CVE-2012-3972.html" source="CVE"/>
        <reference ref_id="CVE-2012-3978" ref_url="http://linux.oracle.com/cve/CVE-2012-3978.html" source="CVE"/>
        <reference ref_id="CVE-2012-3980" ref_url="http://linux.oracle.com/cve/CVE-2012-3980.html" source="CVE"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:41.935-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:38.327-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:58.029-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23230 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.802-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:47.656-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:31:32.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:31:32.177-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:106366"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:106667"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23229" version="21" class="patch">
      <metadata>
        <title>ELSA-2011:0492: python security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>python</product>
        </affected>
        <reference ref_id="ELSA-2011:0492-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0492.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3720" ref_url="http://linux.oracle.com/cve/CVE-2009-3720.html" source="CVE"/>
        <reference ref_id="CVE-2010-3493" ref_url="http://linux.oracle.com/cve/CVE-2010-3493.html" source="CVE"/>
        <reference ref_id="CVE-2011-1015" ref_url="http://linux.oracle.com/cve/CVE-2011-1015.html" source="CVE"/>
        <reference ref_id="CVE-2011-1521" ref_url="http://linux.oracle.com/cve/CVE-2011-1521.html" source="CVE"/>
        <description>The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:26.299-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:38.216-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:57.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23229 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:59.241-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:47.481-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="python-devel is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:104986"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:105009"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:104815"/>
          <criterion comment="python is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:105006"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-44.el5" test_ref="oval:org.mitre.oval:tst:104978"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23228" version="53" class="patch">
      <metadata>
        <title>ELSA-2011:0511: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0511-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0511.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0579" ref_url="http://linux.oracle.com/cve/CVE-2011-0579.html" source="CVE"/>
        <reference ref_id="CVE-2011-0618" ref_url="http://linux.oracle.com/cve/CVE-2011-0618.html" source="CVE"/>
        <reference ref_id="CVE-2011-0619" ref_url="http://linux.oracle.com/cve/CVE-2011-0619.html" source="CVE"/>
        <reference ref_id="CVE-2011-0620" ref_url="http://linux.oracle.com/cve/CVE-2011-0620.html" source="CVE"/>
        <reference ref_id="CVE-2011-0621" ref_url="http://linux.oracle.com/cve/CVE-2011-0621.html" source="CVE"/>
        <reference ref_id="CVE-2011-0622" ref_url="http://linux.oracle.com/cve/CVE-2011-0622.html" source="CVE"/>
        <reference ref_id="CVE-2011-0623" ref_url="http://linux.oracle.com/cve/CVE-2011-0623.html" source="CVE"/>
        <reference ref_id="CVE-2011-0624" ref_url="http://linux.oracle.com/cve/CVE-2011-0624.html" source="CVE"/>
        <reference ref_id="CVE-2011-0625" ref_url="http://linux.oracle.com/cve/CVE-2011-0625.html" source="CVE"/>
        <reference ref_id="CVE-2011-0626" ref_url="http://linux.oracle.com/cve/CVE-2011-0626.html" source="CVE"/>
        <reference ref_id="CVE-2011-0627" ref_url="http://linux.oracle.com/cve/CVE-2011-0627.html" source="CVE"/>
        <reference ref_id="CVE-2011-0628" ref_url="http://linux.oracle.com/cve/CVE-2011-0628.html" source="CVE"/>
        <description>Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code via ActionScript that improperly handles a long array object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:15.981-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:37.957-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:57.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23228 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:59.131-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:47.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.14-1.el5" test_ref="oval:org.mitre.oval:tst:104967"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.14-1.el6" test_ref="oval:org.mitre.oval:tst:104984"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23226" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1438: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1438-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1438.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3648" ref_url="http://linux.oracle.com/cve/CVE-2011-3648.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:37.820-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:37.813-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:57.031-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23226 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:00.512-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:46.951-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-27.el5_7" test_ref="oval:org.mitre.oval:tst:105043"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23224" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0968: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2010:0968-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0968.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3767" ref_url="http://linux.oracle.com/cve/CVE-2010-3767.html" source="CVE"/>
        <reference ref_id="CVE-2010-3772" ref_url="http://linux.oracle.com/cve/CVE-2010-3772.html" source="CVE"/>
        <reference ref_id="CVE-2010-3776" ref_url="http://linux.oracle.com/cve/CVE-2010-3776.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:30.481-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:37.640-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:56.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23224 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:58.815-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:46.744-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-13.el5_5" test_ref="oval:org.mitre.oval:tst:104116"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23222" version="29" class="patch">
      <metadata>
        <title>ELSA-2013:1307: php53 security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference ref_id="ELSA-2013:1307-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1307.html" source="VENDOR"/>
        <reference ref_id="CVE-2006-7243" ref_url="http://linux.oracle.com/cve/CVE-2006-7243.html" source="CVE"/>
        <reference ref_id="CVE-2011-1398" ref_url="http://linux.oracle.com/cve/CVE-2011-1398.html" source="CVE"/>
        <reference ref_id="CVE-2012-0831" ref_url="http://linux.oracle.com/cve/CVE-2012-0831.html" source="CVE"/>
        <reference ref_id="CVE-2012-2688" ref_url="http://linux.oracle.com/cve/CVE-2012-2688.html" source="CVE"/>
        <reference ref_id="CVE-2013-1643" ref_url="http://linux.oracle.com/cve/CVE-2013-1643.html" source="CVE"/>
        <reference ref_id="CVE-2013-4248" ref_url="http://linux.oracle.com/cve/CVE-2013-4248.html" source="CVE"/>
        <description>The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:42.454-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:37.165-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:55.938-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23222 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:58.074-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:46.153-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php53-odbc is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107484"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107535"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107278"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107401"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107475"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107629"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107786"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107477"/>
          <criterion comment="php53 is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107795"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107791"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107755"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107709"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107459"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107779"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107796"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107168"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107551"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107547"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107523"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107701"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-21.el5" test_ref="oval:org.mitre.oval:tst:107147"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23221" version="174" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1434: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2011:1434-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1434.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2094" ref_url="http://linux.oracle.com/cve/CVE-2011-2094.html" source="CVE"/>
        <reference ref_id="CVE-2011-2095" ref_url="http://linux.oracle.com/cve/CVE-2011-2095.html" source="CVE"/>
        <reference ref_id="CVE-2011-2096" ref_url="http://linux.oracle.com/cve/CVE-2011-2096.html" source="CVE"/>
        <reference ref_id="CVE-2011-2097" ref_url="http://linux.oracle.com/cve/CVE-2011-2097.html" source="CVE"/>
        <reference ref_id="CVE-2011-2098" ref_url="http://linux.oracle.com/cve/CVE-2011-2098.html" source="CVE"/>
        <reference ref_id="CVE-2011-2099" ref_url="http://linux.oracle.com/cve/CVE-2011-2099.html" source="CVE"/>
        <reference ref_id="CVE-2011-2101" ref_url="http://linux.oracle.com/cve/CVE-2011-2101.html" source="CVE"/>
        <reference ref_id="CVE-2011-2104" ref_url="http://linux.oracle.com/cve/CVE-2011-2104.html" source="CVE"/>
        <reference ref_id="CVE-2011-2105" ref_url="http://linux.oracle.com/cve/CVE-2011-2105.html" source="CVE"/>
        <reference ref_id="CVE-2011-2107" ref_url="http://linux.oracle.com/cve/CVE-2011-2107.html" source="CVE"/>
        <reference ref_id="CVE-2011-2130" ref_url="http://linux.oracle.com/cve/CVE-2011-2130.html" source="CVE"/>
        <reference ref_id="CVE-2011-2134" ref_url="http://linux.oracle.com/cve/CVE-2011-2134.html" source="CVE"/>
        <reference ref_id="CVE-2011-2135" ref_url="http://linux.oracle.com/cve/CVE-2011-2135.html" source="CVE"/>
        <reference ref_id="CVE-2011-2136" ref_url="http://linux.oracle.com/cve/CVE-2011-2136.html" source="CVE"/>
        <reference ref_id="CVE-2011-2137" ref_url="http://linux.oracle.com/cve/CVE-2011-2137.html" source="CVE"/>
        <reference ref_id="CVE-2011-2138" ref_url="http://linux.oracle.com/cve/CVE-2011-2138.html" source="CVE"/>
        <reference ref_id="CVE-2011-2139" ref_url="http://linux.oracle.com/cve/CVE-2011-2139.html" source="CVE"/>
        <reference ref_id="CVE-2011-2140" ref_url="http://linux.oracle.com/cve/CVE-2011-2140.html" source="CVE"/>
        <reference ref_id="CVE-2011-2414" ref_url="http://linux.oracle.com/cve/CVE-2011-2414.html" source="CVE"/>
        <reference ref_id="CVE-2011-2415" ref_url="http://linux.oracle.com/cve/CVE-2011-2415.html" source="CVE"/>
        <reference ref_id="CVE-2011-2416" ref_url="http://linux.oracle.com/cve/CVE-2011-2416.html" source="CVE"/>
        <reference ref_id="CVE-2011-2417" ref_url="http://linux.oracle.com/cve/CVE-2011-2417.html" source="CVE"/>
        <reference ref_id="CVE-2011-2424" ref_url="http://linux.oracle.com/cve/CVE-2011-2424.html" source="CVE"/>
        <reference ref_id="CVE-2011-2425" ref_url="http://linux.oracle.com/cve/CVE-2011-2425.html" source="CVE"/>
        <reference ref_id="CVE-2011-2426" ref_url="http://linux.oracle.com/cve/CVE-2011-2426.html" source="CVE"/>
        <reference ref_id="CVE-2011-2427" ref_url="http://linux.oracle.com/cve/CVE-2011-2427.html" source="CVE"/>
        <reference ref_id="CVE-2011-2428" ref_url="http://linux.oracle.com/cve/CVE-2011-2428.html" source="CVE"/>
        <reference ref_id="CVE-2011-2429" ref_url="http://linux.oracle.com/cve/CVE-2011-2429.html" source="CVE"/>
        <reference ref_id="CVE-2011-2430" ref_url="http://linux.oracle.com/cve/CVE-2011-2430.html" source="CVE"/>
        <reference ref_id="CVE-2011-2431" ref_url="http://linux.oracle.com/cve/CVE-2011-2431.html" source="CVE"/>
        <reference ref_id="CVE-2011-2432" ref_url="http://linux.oracle.com/cve/CVE-2011-2432.html" source="CVE"/>
        <reference ref_id="CVE-2011-2433" ref_url="http://linux.oracle.com/cve/CVE-2011-2433.html" source="CVE"/>
        <reference ref_id="CVE-2011-2434" ref_url="http://linux.oracle.com/cve/CVE-2011-2434.html" source="CVE"/>
        <reference ref_id="CVE-2011-2435" ref_url="http://linux.oracle.com/cve/CVE-2011-2435.html" source="CVE"/>
        <reference ref_id="CVE-2011-2436" ref_url="http://linux.oracle.com/cve/CVE-2011-2436.html" source="CVE"/>
        <reference ref_id="CVE-2011-2437" ref_url="http://linux.oracle.com/cve/CVE-2011-2437.html" source="CVE"/>
        <reference ref_id="CVE-2011-2438" ref_url="http://linux.oracle.com/cve/CVE-2011-2438.html" source="CVE"/>
        <reference ref_id="CVE-2011-2439" ref_url="http://linux.oracle.com/cve/CVE-2011-2439.html" source="CVE"/>
        <reference ref_id="CVE-2011-2440" ref_url="http://linux.oracle.com/cve/CVE-2011-2440.html" source="CVE"/>
        <reference ref_id="CVE-2011-2442" ref_url="http://linux.oracle.com/cve/CVE-2011-2442.html" source="CVE"/>
        <reference ref_id="CVE-2011-2444" ref_url="http://linux.oracle.com/cve/CVE-2011-2444.html" source="CVE"/>
        <reference ref_id="CVE-2011-4374" ref_url="http://linux.oracle.com/cve/CVE-2011-4374.html" source="CVE"/>
        <description>Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:32.274-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:36.267-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:54.205-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23221 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:47:58.633-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:45.045-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:30:57.651-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:30:57.651-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:105264"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:105490"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:105385"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:105425"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23220" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1256: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference ref_id="ELSA-2012:1256-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1256.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4405" ref_url="http://linux.oracle.com/cve/CVE-2012-4405.html" source="CVE"/>
        <description>Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow.  NOTE: this issue is also described as an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:36.140-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:36.191-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:54.091-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23220 - optimisation of Oracle Linux content" date="2014-05-05T17:46:00.349-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:48:01.471-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:44.938-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:30:18.502-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:30:18.502-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:106032"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:106564"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:106750"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:106650"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:106679"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:106385"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:106740"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23219" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0199: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2011:0199-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0199.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0281" ref_url="http://linux.oracle.com/cve/CVE-2011-0281.html" source="CVE"/>
        <reference ref_id="CVE-2011-0282" ref_url="http://linux.oracle.com/cve/CVE-2011-0282.html" source="CVE"/>
        <description>The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted principal name.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:07.127-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:36.101-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:53.948-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23219 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:15.643-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:55.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:104639"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:104630"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:104736"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:103892"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:104749"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-55.el5_6.1" test_ref="oval:org.mitre.oval:tst:104819"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23215" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0134: freeradius2 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>freeradius2</product>
        </affected>
        <reference ref_id="ELSA-2013:0134-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0134.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4966" ref_url="http://linux.oracle.com/cve/CVE-2011-4966.html" source="CVE"/>
        <description>modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:59.997-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:35.176-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:52.275-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23215 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.453-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:44.026-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="freeradius2 is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:107051"/>
          <criterion comment="freeradius2-ldap is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:107094"/>
          <criterion comment="freeradius2-unixODBC is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:106945"/>
          <criterion comment="freeradius2-perl is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:106870"/>
          <criterion comment="freeradius2-python is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:106916"/>
          <criterion comment="freeradius2-utils is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:106773"/>
          <criterion comment="freeradius2-postgresql is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:106855"/>
          <criterion comment="freeradius2-mysql is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:106872"/>
          <criterion comment="freeradius2-krb5 is earlier than 0:2.1.12-5.el5" test_ref="oval:org.mitre.oval:tst:106988"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23214" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:0017: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:0017-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0017.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4008" ref_url="http://linux.oracle.com/cve/CVE-2010-4008.html" source="CVE"/>
        <reference ref_id="CVE-2011-0216" ref_url="http://linux.oracle.com/cve/CVE-2011-0216.html" source="CVE"/>
        <reference ref_id="CVE-2011-1944" ref_url="http://linux.oracle.com/cve/CVE-2011-1944.html" source="CVE"/>
        <reference ref_id="CVE-2011-2834" ref_url="http://linux.oracle.com/cve/CVE-2011-2834.html" source="CVE"/>
        <reference ref_id="CVE-2011-3905" ref_url="http://linux.oracle.com/cve/CVE-2011-3905.html" source="CVE"/>
        <reference ref_id="CVE-2011-3919" ref_url="http://linux.oracle.com/cve/CVE-2011-3919.html" source="CVE"/>
        <description>Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:59.758-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:34.971-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:51.973-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23214 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:32.744-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:43.838-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.12.el5_7.2" test_ref="oval:org.mitre.oval:tst:105610"/>
          <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.12.el5_7.2" test_ref="oval:org.mitre.oval:tst:105666"/>
          <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.12.el5_7.2" test_ref="oval:org.mitre.oval:tst:105589"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23213" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0451: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0451-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0451.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0611" ref_url="http://linux.oracle.com/cve/CVE-2011-0611.html" source="CVE"/>
        <description>Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:35.364-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:34.905-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:51.864-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23213 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.356-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:43.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el5" test_ref="oval:org.mitre.oval:tst:108730"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el6" test_ref="oval:org.mitre.oval:tst:108167"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23212" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0715: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0715-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0715.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3101" ref_url="http://linux.oracle.com/cve/CVE-2011-3101.html" source="CVE"/>
        <reference ref_id="CVE-2012-1937" ref_url="http://linux.oracle.com/cve/CVE-2012-1937.html" source="CVE"/>
        <reference ref_id="CVE-2012-1938" ref_url="http://linux.oracle.com/cve/CVE-2012-1938.html" source="CVE"/>
        <reference ref_id="CVE-2012-1939" ref_url="http://linux.oracle.com/cve/CVE-2012-1939.html" source="CVE"/>
        <reference ref_id="CVE-2012-1940" ref_url="http://linux.oracle.com/cve/CVE-2012-1940.html" source="CVE"/>
        <reference ref_id="CVE-2012-1941" ref_url="http://linux.oracle.com/cve/CVE-2012-1941.html" source="CVE"/>
        <reference ref_id="CVE-2012-1944" ref_url="http://linux.oracle.com/cve/CVE-2012-1944.html" source="CVE"/>
        <reference ref_id="CVE-2012-1945" ref_url="http://linux.oracle.com/cve/CVE-2012-1945.html" source="CVE"/>
        <reference ref_id="CVE-2012-1946" ref_url="http://linux.oracle.com/cve/CVE-2012-1946.html" source="CVE"/>
        <reference ref_id="CVE-2012-1947" ref_url="http://linux.oracle.com/cve/CVE-2012-1947.html" source="CVE"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:16.115-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:34.686-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:51.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23212 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.383-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:43.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el5_8" test_ref="oval:org.mitre.oval:tst:106356"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el6_2" test_ref="oval:org.mitre.oval:tst:105796"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23211" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1302: xinetd security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xinetd</product>
        </affected>
        <reference ref_id="ELSA-2013:1302-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1302.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0862" ref_url="http://linux.oracle.com/cve/CVE-2012-0862.html" source="CVE"/>
        <description>builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:27.312-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:34.628-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:51.298-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23211 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.892-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:43.281-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="xinetd is earlier than 2:2.3.14-19.el5" test_ref="oval:org.mitre.oval:tst:107678"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23210" version="49" class="patch">
      <metadata>
        <title>ELSA-2010:0825: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2010:0825-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0825.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3677" ref_url="http://linux.oracle.com/cve/CVE-2010-3677.html" source="CVE"/>
        <reference ref_id="CVE-2010-3680" ref_url="http://linux.oracle.com/cve/CVE-2010-3680.html" source="CVE"/>
        <reference ref_id="CVE-2010-3681" ref_url="http://linux.oracle.com/cve/CVE-2010-3681.html" source="CVE"/>
        <reference ref_id="CVE-2010-3682" ref_url="http://linux.oracle.com/cve/CVE-2010-3682.html" source="CVE"/>
        <reference ref_id="CVE-2010-3833" ref_url="http://linux.oracle.com/cve/CVE-2010-3833.html" source="CVE"/>
        <reference ref_id="CVE-2010-3835" ref_url="http://linux.oracle.com/cve/CVE-2010-3835.html" source="CVE"/>
        <reference ref_id="CVE-2010-3836" ref_url="http://linux.oracle.com/cve/CVE-2010-3836.html" source="CVE"/>
        <reference ref_id="CVE-2010-3837" ref_url="http://linux.oracle.com/cve/CVE-2010-3837.html" source="CVE"/>
        <reference ref_id="CVE-2010-3838" ref_url="http://linux.oracle.com/cve/CVE-2010-3838.html" source="CVE"/>
        <reference ref_id="CVE-2010-3839" ref_url="http://linux.oracle.com/cve/CVE-2010-3839.html" source="CVE"/>
        <reference ref_id="CVE-2010-3840" ref_url="http://linux.oracle.com/cve/CVE-2010-3840.html" source="CVE"/>
        <description>The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:28.130-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:34.382-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:50.809-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23210 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:32.169-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:42.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:104397"/>
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:104449"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:104450"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:103526"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.4" test_ref="oval:org.mitre.oval:tst:104426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23208" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1317: cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference ref_id="ELSA-2011:1317-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1317.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3208" ref_url="http://linux.oracle.com/cve/CVE-2011-3208.html" source="CVE"/>
        <description>Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:26.243-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:34.207-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:50.483-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23208 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:29.474-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:42.483-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:29:30.044-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:29:30.044-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:104721"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:104584"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:105354"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:104375"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105351"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105237"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23207" version="33" class="patch">
      <metadata>
        <title>ELSA-2012:0033: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0033-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0033.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0708" ref_url="http://linux.oracle.com/cve/CVE-2011-0708.html" source="CVE"/>
        <reference ref_id="CVE-2011-1148" ref_url="http://linux.oracle.com/cve/CVE-2011-1148.html" source="CVE"/>
        <reference ref_id="CVE-2011-1466" ref_url="http://linux.oracle.com/cve/CVE-2011-1466.html" source="CVE"/>
        <reference ref_id="CVE-2011-1469" ref_url="http://linux.oracle.com/cve/CVE-2011-1469.html" source="CVE"/>
        <reference ref_id="CVE-2011-2202" ref_url="http://linux.oracle.com/cve/CVE-2011-2202.html" source="CVE"/>
        <reference ref_id="CVE-2011-4566" ref_url="http://linux.oracle.com/cve/CVE-2011-4566.html" source="CVE"/>
        <reference ref_id="CVE-2011-4885" ref_url="http://linux.oracle.com/cve/CVE-2011-4885.html" source="CVE"/>
        <description>PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:05.513-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:33.995-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:50.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23207 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.594-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:42.240-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105638"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:104739"/>
          <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105546"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105083"/>
          <criterion comment="php is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105417"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105444"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105509"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105026"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105690"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105655"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105470"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105545"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105204"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105565"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105289"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105005"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105526"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105619"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.4" test_ref="oval:org.mitre.oval:tst:105703"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23206" version="65" class="patch">
      <metadata>
        <title>ELSA-2010:0829: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2010:0829-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0829.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3636" ref_url="http://linux.oracle.com/cve/CVE-2010-3636.html" source="CVE"/>
        <reference ref_id="CVE-2010-3639" ref_url="http://linux.oracle.com/cve/CVE-2010-3639.html" source="CVE"/>
        <reference ref_id="CVE-2010-3640" ref_url="http://linux.oracle.com/cve/CVE-2010-3640.html" source="CVE"/>
        <reference ref_id="CVE-2010-3641" ref_url="http://linux.oracle.com/cve/CVE-2010-3641.html" source="CVE"/>
        <reference ref_id="CVE-2010-3642" ref_url="http://linux.oracle.com/cve/CVE-2010-3642.html" source="CVE"/>
        <reference ref_id="CVE-2010-3643" ref_url="http://linux.oracle.com/cve/CVE-2010-3643.html" source="CVE"/>
        <reference ref_id="CVE-2010-3644" ref_url="http://linux.oracle.com/cve/CVE-2010-3644.html" source="CVE"/>
        <reference ref_id="CVE-2010-3645" ref_url="http://linux.oracle.com/cve/CVE-2010-3645.html" source="CVE"/>
        <reference ref_id="CVE-2010-3646" ref_url="http://linux.oracle.com/cve/CVE-2010-3646.html" source="CVE"/>
        <reference ref_id="CVE-2010-3647" ref_url="http://linux.oracle.com/cve/CVE-2010-3647.html" source="CVE"/>
        <reference ref_id="CVE-2010-3648" ref_url="http://linux.oracle.com/cve/CVE-2010-3648.html" source="CVE"/>
        <reference ref_id="CVE-2010-3649" ref_url="http://linux.oracle.com/cve/CVE-2010-3649.html" source="CVE"/>
        <reference ref_id="CVE-2010-3650" ref_url="http://linux.oracle.com/cve/CVE-2010-3650.html" source="CVE"/>
        <reference ref_id="CVE-2010-3652" ref_url="http://linux.oracle.com/cve/CVE-2010-3652.html" source="CVE"/>
        <reference ref_id="CVE-2010-3654" ref_url="http://linux.oracle.com/cve/CVE-2010-3654.html" source="CVE"/>
        <description>Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:31.977-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:33.594-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:49.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23206 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:34.165-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:41.781-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="flash-plugin is earlier than 0:10.1.102.64-1.el5" test_ref="oval:org.mitre.oval:tst:104445"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23205" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0019: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0019-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0019.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4566" ref_url="http://linux.oracle.com/cve/CVE-2011-4566.html" source="CVE"/>
        <reference ref_id="CVE-2011-4885" ref_url="http://linux.oracle.com/cve/CVE-2011-4885.html" source="CVE"/>
        <description>PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:57.186-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:33.403-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:49.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23205 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:32.575-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:41.544-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:28:41.029-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:28:41.029-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105463"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105157"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105085"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105600"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105281"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105082"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105647"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105532"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105665"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105370"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105525"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105140"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105482"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105097"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:104957"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105177"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105606"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105471"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105561"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105579"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105700"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:104852"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105553"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105426"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105624"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:105389"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105654"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105584"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105676"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105629"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105466"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105438"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105697"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105398"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105689"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:104712"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105416"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105304"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105408"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105686"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105450"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105605"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105368"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105628"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105679"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:104757"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:105362"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23204" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0507: apr security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference ref_id="ELSA-2011:0507-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0507.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0419" ref_url="http://linux.oracle.com/cve/CVE-2011-0419.html" source="CVE"/>
        <description>Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:16.340-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:33.323-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:49.183-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23204 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.280-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:41.417-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:25:49.679-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:25:49.679-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:104494"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:104968"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:104814"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104786"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:105030"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23203" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1813: php53 and php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:1813-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1813.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6420" ref_url="http://linux.oracle.com/cve/CVE-2013-6420.html" source="CVE"/>
        <description>The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:30.413-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:33.165-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:48.973-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23203 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:34.545-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:41.225-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:25:03.721-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:25:03.721-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-intl is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107591"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107603"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107923"/>
            <criterion comment="php53 is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107473"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107790"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107903"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107976"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107847"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107320"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107539"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107446"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107917"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107982"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107136"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107862"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107921"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107594"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107885"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107561"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107960"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:107317"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107706"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107866"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107840"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107248"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107135"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107518"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107926"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107378"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107752"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107897"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107956"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107120"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107609"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107751"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107455"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:108006"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107037"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107732"/>
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107773"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107930"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107873"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107001"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107869"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107945"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107927"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107932"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:107641"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23202" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1479: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:1479-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1479.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1162" ref_url="http://linux.oracle.com/cve/CVE-2011-1162.html" source="CVE"/>
        <reference ref_id="CVE-2011-1898" ref_url="http://linux.oracle.com/cve/CVE-2011-1898.html" source="CVE"/>
        <reference ref_id="CVE-2011-2203" ref_url="http://linux.oracle.com/cve/CVE-2011-2203.html" source="CVE"/>
        <reference ref_id="CVE-2011-2494" ref_url="http://linux.oracle.com/cve/CVE-2011-2494.html" source="CVE"/>
        <reference ref_id="CVE-2011-3363" ref_url="http://linux.oracle.com/cve/CVE-2011-3363.html" source="CVE"/>
        <reference ref_id="CVE-2011-4110" ref_url="http://linux.oracle.com/cve/CVE-2011-4110.html" source="CVE"/>
        <description>The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:30.697-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:32.959-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:48.637-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23202 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.653-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:40.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:104960"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:104709"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105533"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105531"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105305"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105522"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:104588"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105294"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:104958"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105266"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105554"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.12.1.el5" test_ref="oval:org.mitre.oval:tst:105137"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23200" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1000: rgmanager security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>rgmanager</product>
        </affected>
        <reference ref_id="ELSA-2011:1000-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1000.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3389" ref_url="http://linux.oracle.com/cve/CVE-2010-3389.html" source="CVE"/>
        <description>The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:17.241-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:32.766-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:48.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23200 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.789-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:40.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="rgmanager is earlier than 0:2.0.52-21.el5" test_ref="oval:org.mitre.oval:tst:105023"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23199" version="98" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010:0987: java-1.6.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0987-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0987.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-1321" ref_url="http://linux.oracle.com/cve/CVE-2010-1321.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3550" ref_url="http://linux.oracle.com/cve/CVE-2010-3550.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3555" ref_url="http://linux.oracle.com/cve/CVE-2010-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-3556" ref_url="http://linux.oracle.com/cve/CVE-2010-3556.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3558" ref_url="http://linux.oracle.com/cve/CVE-2010-3558.html" source="CVE"/>
        <reference ref_id="CVE-2010-3560" ref_url="http://linux.oracle.com/cve/CVE-2010-3560.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3563" ref_url="http://linux.oracle.com/cve/CVE-2010-3563.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3566" ref_url="http://linux.oracle.com/cve/CVE-2010-3566.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <reference ref_id="CVE-2010-3572" ref_url="http://linux.oracle.com/cve/CVE-2010-3572.html" source="CVE"/>
        <reference ref_id="CVE-2010-3573" ref_url="http://linux.oracle.com/cve/CVE-2010-3573.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:27.395-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:32.219-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:47.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23199 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:33.555-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:40.058-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:22:01.500-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:22:01.500-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103990"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104267"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104055"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104215"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103958"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104194"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104493"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:104453"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:104380"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:104561"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:103903"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:104214"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:104342"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:104459"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:104482"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23197" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1264: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1264-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1264.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3488" ref_url="http://linux.oracle.com/cve/CVE-2012-3488.html" source="CVE"/>
        <description>The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:46.386-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:32.087-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:47.038-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23197 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.060-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:39.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql-server is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106851"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106165"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106878"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106240"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106857"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106812"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106707"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106415"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106540"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-6.el5_8" test_ref="oval:org.mitre.oval:tst:106629"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23196" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1402: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2011:1402-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1402.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3256" ref_url="http://linux.oracle.com/cve/CVE-2011-3256.html" source="CVE"/>
        <description>FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a different vulnerability than CVE-2011-0226.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:00.926-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:32.010-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:46.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23196 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:29.996-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:39.753-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:20:41.041-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:20:41.041-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:108977"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:109006"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:109304"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:109495"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:109502"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:108883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23194" version="38" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1269: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1269-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1269.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1718" ref_url="http://linux.oracle.com/cve/CVE-2013-1718.html" source="CVE"/>
        <reference ref_id="CVE-2013-1722" ref_url="http://linux.oracle.com/cve/CVE-2013-1722.html" source="CVE"/>
        <reference ref_id="CVE-2013-1725" ref_url="http://linux.oracle.com/cve/CVE-2013-1725.html" source="CVE"/>
        <reference ref_id="CVE-2013-1730" ref_url="http://linux.oracle.com/cve/CVE-2013-1730.html" source="CVE"/>
        <reference ref_id="CVE-2013-1732" ref_url="http://linux.oracle.com/cve/CVE-2013-1732.html" source="CVE"/>
        <reference ref_id="CVE-2013-1735" ref_url="http://linux.oracle.com/cve/CVE-2013-1735.html" source="CVE"/>
        <reference ref_id="CVE-2013-1736" ref_url="http://linux.oracle.com/cve/CVE-2013-1736.html" source="CVE"/>
        <reference ref_id="CVE-2013-1737" ref_url="http://linux.oracle.com/cve/CVE-2013-1737.html" source="CVE"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:34.801-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:31.557-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:46.044-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23194 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:29.893-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:39.124-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:19:58.767-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:19:58.767-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:107698"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:107417"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23193" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0898: kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2010:0898-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0898.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3698" ref_url="http://linux.oracle.com/cve/CVE-2010-3698.html" source="CVE"/>
        <description>The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor Table (LDT).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:32.886-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:31.478-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:45.976-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23193 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:33.380-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:39.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:103849"/>
          <criterion comment="kvm is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:104010"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:104088"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.el5_5.25" test_ref="oval:org.mitre.oval:tst:104436"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23192" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0306: samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference ref_id="ELSA-2011:0306-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0306.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0719" ref_url="http://linux.oracle.com/cve/CVE-2011-0719.html" source="CVE"/>
        <description>Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:01.099-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:31.402-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:45.809-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23192 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:29.275-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:38.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="samba3x-swat is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:103954"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:104730"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:104816"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:104767"/>
          <criterion comment="samba3x is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:104745"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:104794"/>
          <criterion comment="samba3x-common is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:104676"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.4-0.70.el5_6.1" test_ref="oval:org.mitre.oval:tst:104903"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23191" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0394: conga security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference ref_id="ELSA-2011:0394-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0394.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0720" ref_url="http://linux.oracle.com/cve/CVE-2011-0720.html" source="CVE"/>
        <description>Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:08.724-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:31.334-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:45.706-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23191 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.961-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:38.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ricci is earlier than 0:0.12.2-24.el5_6.1" test_ref="oval:org.mitre.oval:tst:104837"/>
          <criterion comment="luci is earlier than 0:0.12.2-24.el5_6.1" test_ref="oval:org.mitre.oval:tst:104202"/>
          <criterion comment="conga is earlier than 0:0.12.2-24.el5_6.1" test_ref="oval:org.mitre.oval:tst:104909"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23189" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0092: php53 security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference ref_id="ELSA-2012:0092-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0092.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0830" ref_url="http://linux.oracle.com/cve/CVE-2012-0830.html" source="CVE"/>
        <description>The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.	 NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:02.930-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:31.135-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:45.415-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23189 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:33.025-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:38.533-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105722"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105615"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105741"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105696"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105528"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105616"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105728"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105660"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105523"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105448"/>
          <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105552"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105653"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105691"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105681"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105263"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105540"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105639"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105658"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105427"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105694"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.6" test_ref="oval:org.mitre.oval:tst:105148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23188" version="34" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1478: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1478-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1478.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3545" ref_url="http://linux.oracle.com/cve/CVE-2011-3545.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3549" ref_url="http://linux.oracle.com/cve/CVE-2011-3549.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:39.992-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.952-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:45.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23188 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.198-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:38.411-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:19:27.832-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:19:27.832-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105302"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104944"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104880"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105453"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105310"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105010"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104560"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104964"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105445"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105424"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105443"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105190"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105557"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105353"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23187" version="26" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0697: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0697-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0697.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0788" ref_url="http://linux.oracle.com/cve/CVE-2013-0788.html" source="CVE"/>
        <reference ref_id="CVE-2013-0793" ref_url="http://linux.oracle.com/cve/CVE-2013-0793.html" source="CVE"/>
        <reference ref_id="CVE-2013-0795" ref_url="http://linux.oracle.com/cve/CVE-2013-0795.html" source="CVE"/>
        <reference ref_id="CVE-2013-0796" ref_url="http://linux.oracle.com/cve/CVE-2013-0796.html" source="CVE"/>
        <reference ref_id="CVE-2013-0800" ref_url="http://linux.oracle.com/cve/CVE-2013-0800.html" source="CVE"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:44.024-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.820-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:44.997-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23187 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.548-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:38.191-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:18:14.163-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:18:14.163-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:107193"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:107326"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23186" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0533: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2012:0533-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0533.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2111" ref_url="http://linux.oracle.com/cve/CVE-2012-2111.html" source="CVE"/>
        <description>The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:59.102-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.721-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:44.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23186 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:34.369-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:38.091-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:106091"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:105182"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:106082"/>
            <criterion comment="samba3x is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:106116"/>
            <criterion comment="samba3x-client is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:106028"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:105473"/>
            <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:105867"/>
            <criterion comment="samba3x-common is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:105955"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:105283"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:105791"/>
            <criterion comment="samba is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:106008"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:105663"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:106164"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:105974"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:106052"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:105369"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:106169"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:106121"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:105258"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:106077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23185" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1102: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2012:1102-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1102.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1178" ref_url="http://linux.oracle.com/cve/CVE-2012-1178.html" source="CVE"/>
        <reference ref_id="CVE-2012-2318" ref_url="http://linux.oracle.com/cve/CVE-2012-2318.html" source="CVE"/>
        <reference ref_id="CVE-2012-3374" ref_url="http://linux.oracle.com/cve/CVE-2012-3374.html" source="CVE"/>
        <description>Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:09.367-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.602-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:44.639-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23185 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:33.260-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:37.899-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:17:41.565-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:17:41.565-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106656"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106670"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:105754"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106615"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106722"/>
            <criterion comment="finch is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106500"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106725"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106604"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:106681"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106596"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106387"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106134"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106182"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106686"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106526"/>
            <criterion comment="finch is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106341"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106518"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106618"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:106503"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23184" version="21" class="patch">
      <metadata>
        <title>ELSA-2010:0534: libpng security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference ref_id="ELSA-2010:0534-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0534.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2042" ref_url="http://linux.oracle.com/cve/CVE-2009-2042.html" source="CVE"/>
        <reference ref_id="CVE-2010-0205" ref_url="http://linux.oracle.com/cve/CVE-2010-0205.html" source="CVE"/>
        <reference ref_id="CVE-2010-1205" ref_url="http://linux.oracle.com/cve/CVE-2010-1205.html" source="CVE"/>
        <reference ref_id="CVE-2010-2249" ref_url="http://linux.oracle.com/cve/CVE-2010-2249.html" source="CVE"/>
        <description>Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:59.615-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.481-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:44.406-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23184 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.981-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:37.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libpng is earlier than 2:1.2.10-7.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104085"/>
          <criterion comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_5.3" test_ref="oval:org.mitre.oval:tst:103665"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23183" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1267: bind security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1267-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1267.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4244" ref_url="http://linux.oracle.com/cve/CVE-2012-4244.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:47.109-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.410-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:44.303-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23183 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:33.823-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:37.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:106620"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:106565"/>
          <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:106799"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:106365"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:105969"/>
          <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:106625"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:106877"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.4" test_ref="oval:org.mitre.oval:tst:106394"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23182" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0451: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0451-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0451.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0611" ref_url="http://linux.oracle.com/cve/CVE-2011-0611.html" source="CVE"/>
        <description>Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:01.375-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.345-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:44.192-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23182 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:34.263-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:37.446-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:16:08.954-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:16:08.954-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el5" test_ref="oval:org.mitre.oval:tst:104746"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el6" test_ref="oval:org.mitre.oval:tst:104950"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23180" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010:0889: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2010:0889-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0889.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3855" ref_url="http://linux.oracle.com/cve/CVE-2010-3855.html" source="CVE"/>
        <description>Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:30.773-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:30.016-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:43.647-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23180 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.183-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:37.054-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:15:37.711-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:15:37.711-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:104472"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:104457"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:104075"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:104419"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:104473"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:104412"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23178" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0028: kvm security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2011:0028-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0028.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4525" ref_url="http://linux.oracle.com/cve/CVE-2010-4525.html" source="CVE"/>
        <description>Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:09.574-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:29.824-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:43.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23178 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.095-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:36.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kvm-qemu-img is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:103872"/>
          <criterion comment="kvm is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:104409"/>
          <criterion comment="kmod-kvm is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:104502"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:104490"/>
          <criterion comment="kvm-tools is earlier than 0:83-224.el5" test_ref="oval:org.mitre.oval:tst:104536"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23177" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:1791: nss and nspr security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1791-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1791.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1739" ref_url="http://linux.oracle.com/cve/CVE-2013-1739.html" source="CVE"/>
        <reference ref_id="CVE-2013-1741" ref_url="http://linux.oracle.com/cve/CVE-2013-1741.html" source="CVE"/>
        <reference ref_id="CVE-2013-5605" ref_url="http://linux.oracle.com/cve/CVE-2013-5605.html" source="CVE"/>
        <reference ref_id="CVE-2013-5606" ref_url="http://linux.oracle.com/cve/CVE-2013-5606.html" source="CVE"/>
        <reference ref_id="CVE-2013-5607" ref_url="http://linux.oracle.com/cve/CVE-2013-5607.html" source="CVE"/>
        <description>Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:36.473-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:29.667-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:43.111-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23177 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:34.735-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:36.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr-devel is earlier than 0:4.10.2-2.el5_10" test_ref="oval:org.mitre.oval:tst:106983"/>
          <criterion comment="nspr is earlier than 0:4.10.2-2.el5_10" test_ref="oval:org.mitre.oval:tst:107461"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:107808"/>
          <criterion comment="nss-tools is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:107402"/>
          <criterion comment="nss-devel is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:107942"/>
          <criterion comment="nss is earlier than 0:3.15.3-3.el5_10" test_ref="oval:org.mitre.oval:tst:107940"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23176" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0025: gcc security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gcc</product>
        </affected>
        <reference ref_id="ELSA-2011:0025-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0025.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0831" ref_url="http://linux.oracle.com/cve/CVE-2010-0831.html" source="CVE"/>
        <reference ref_id="CVE-2010-2322" ref_url="http://linux.oracle.com/cve/CVE-2010-2322.html" source="CVE"/>
        <description>Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831.	NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:14.685-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:29.524-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:42.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23176 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:31.783-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:36.411-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libgcj-src is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:103805"/>
          <criterion comment="gcc-objc++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104605"/>
          <criterion comment="libgfortran is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104296"/>
          <criterion comment="libmudflap is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104505"/>
          <criterion comment="gcc-gfortran is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104469"/>
          <criterion comment="libgcc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104227"/>
          <criterion comment="libgcj-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104443"/>
          <criterion comment="cpp is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104206"/>
          <criterion comment="gcc-gnat is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104534"/>
          <criterion comment="libstdc++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104533"/>
          <criterion comment="libmudflap-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:103851"/>
          <criterion comment="gcc-objc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104567"/>
          <criterion comment="gcc-c++ is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104640"/>
          <criterion comment="gcc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104246"/>
          <criterion comment="gcc-java is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104543"/>
          <criterion comment="libgnat is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104504"/>
          <criterion comment="libgcj is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104623"/>
          <criterion comment="libstdc++-devel is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104144"/>
          <criterion comment="libobjc is earlier than 0:4.1.2-50.el5" test_ref="oval:org.mitre.oval:tst:104497"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23175" version="33" class="patch">
      <metadata>
        <title>ELSA-2012:0103: squirrelmail security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>squirrelmail</product>
        </affected>
        <reference ref_id="ELSA-2012:0103-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0103.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1637" ref_url="http://linux.oracle.com/cve/CVE-2010-1637.html" source="CVE"/>
        <reference ref_id="CVE-2010-2813" ref_url="http://linux.oracle.com/cve/CVE-2010-2813.html" source="CVE"/>
        <reference ref_id="CVE-2010-4554" ref_url="http://linux.oracle.com/cve/CVE-2010-4554.html" source="CVE"/>
        <reference ref_id="CVE-2010-4555" ref_url="http://linux.oracle.com/cve/CVE-2010-4555.html" source="CVE"/>
        <reference ref_id="CVE-2011-2023" ref_url="http://linux.oracle.com/cve/CVE-2011-2023.html" source="CVE"/>
        <reference ref_id="CVE-2011-2752" ref_url="http://linux.oracle.com/cve/CVE-2011-2752.html" source="CVE"/>
        <reference ref_id="CVE-2011-2753" ref_url="http://linux.oracle.com/cve/CVE-2011-2753.html" source="CVE"/>
        <description>Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the Index Order (aka options_order) page, a different issue than CVE-2010-4555.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:17:55.078-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:29.357-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:42.574-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23175 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.875-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:36.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_7.13" test_ref="oval:org.mitre.oval:tst:105414"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23174" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0121: mysql security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2013:0121-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0121.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4452" ref_url="http://linux.oracle.com/cve/CVE-2012-4452.html" source="CVE"/>
        <description>MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.	 NOTE: this vulnerability exists because of a CVE-2009-4030 regression, which was not omitted in other packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:03.629-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:29.294-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:42.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23174 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:29.561-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:36.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-server is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:106098"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:106594"/>
          <criterion comment="mysql is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:106603"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:106932"/>
          <criterion comment="mysql-test is earlier than 0:5.0.95-3.el5" test_ref="oval:org.mitre.oval:tst:106653"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23173" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0307: util-linux security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>util-linux</product>
        </affected>
        <reference ref_id="ELSA-2012:0307-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0307.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1675" ref_url="http://linux.oracle.com/cve/CVE-2011-1675.html" source="CVE"/>
        <reference ref_id="CVE-2011-1677" ref_url="http://linux.oracle.com/cve/CVE-2011-1677.html" source="CVE"/>
        <description>mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:08.423-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:29.217-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:42.341-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23173 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:30.712-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:36.001-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="util-linux is earlier than 0:2.13-0.59.el5" test_ref="oval:org.mitre.oval:tst:105781"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23171" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1081: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2012:1081-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1081.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2337" ref_url="http://linux.oracle.com/cve/CVE-2012-2337.html" source="CVE"/>
        <description>sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:17.480-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:28.732-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:41.716-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23171 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:33.138-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:35.490-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:14:51.694-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:14:51.694-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8" test_ref="oval:org.mitre.oval:tst:106737"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="sudo is earlier than 0:1.7.4p5-12.el6_3" test_ref="oval:org.mitre.oval:tst:106101"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23170" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0704: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0704-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0704.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3081" ref_url="http://linux.oracle.com/cve/CVE-2010-3081.html" source="CVE"/>
        <description>The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:23.947-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:28.636-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:41.587-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23170 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:29.375-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:35.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:103729"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104292"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104367"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104325"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104110"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:103818"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:103825"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104154"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104269"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104270"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104201"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.4.el5" test_ref="oval:org.mitre.oval:tst:104323"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23169" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1266: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference ref_id="ELSA-2012:1266-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1266.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4244" ref_url="http://linux.oracle.com/cve/CVE-2012-4244.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:41.628-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:28.509-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:41.473-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23169 - optimisation of Oracle Linux content" date="2014-05-05T17:48:00.231-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:49:29.794-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:35.288-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:106659"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:106047"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:106808"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:106885"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.3" test_ref="oval:org.mitre.oval:tst:106769"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23168" version="73" class="patch">
      <metadata>
        <title>ELSA-2010:0400: tetex security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tetex</product>
        </affected>
        <reference ref_id="ELSA-2010:0400-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0400.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-0146" ref_url="http://linux.oracle.com/cve/CVE-2009-0146.html" source="CVE"/>
        <reference ref_id="CVE-2009-0147" ref_url="http://linux.oracle.com/cve/CVE-2009-0147.html" source="CVE"/>
        <reference ref_id="CVE-2009-0166" ref_url="http://linux.oracle.com/cve/CVE-2009-0166.html" source="CVE"/>
        <reference ref_id="CVE-2009-0195" ref_url="http://linux.oracle.com/cve/CVE-2009-0195.html" source="CVE"/>
        <reference ref_id="CVE-2009-0791" ref_url="http://linux.oracle.com/cve/CVE-2009-0791.html" source="CVE"/>
        <reference ref_id="CVE-2009-0799" ref_url="http://linux.oracle.com/cve/CVE-2009-0799.html" source="CVE"/>
        <reference ref_id="CVE-2009-0800" ref_url="http://linux.oracle.com/cve/CVE-2009-0800.html" source="CVE"/>
        <reference ref_id="CVE-2009-1179" ref_url="http://linux.oracle.com/cve/CVE-2009-1179.html" source="CVE"/>
        <reference ref_id="CVE-2009-1180" ref_url="http://linux.oracle.com/cve/CVE-2009-1180.html" source="CVE"/>
        <reference ref_id="CVE-2009-1181" ref_url="http://linux.oracle.com/cve/CVE-2009-1181.html" source="CVE"/>
        <reference ref_id="CVE-2009-1182" ref_url="http://linux.oracle.com/cve/CVE-2009-1182.html" source="CVE"/>
        <reference ref_id="CVE-2009-1183" ref_url="http://linux.oracle.com/cve/CVE-2009-1183.html" source="CVE"/>
        <reference ref_id="CVE-2009-3608" ref_url="http://linux.oracle.com/cve/CVE-2009-3608.html" source="CVE"/>
        <reference ref_id="CVE-2009-3609" ref_url="http://linux.oracle.com/cve/CVE-2009-3609.html" source="CVE"/>
        <reference ref_id="CVE-2010-0739" ref_url="http://linux.oracle.com/cve/CVE-2010-0739.html" source="CVE"/>
        <reference ref_id="CVE-2010-0829" ref_url="http://linux.oracle.com/cve/CVE-2010-0829.html" source="CVE"/>
        <reference ref_id="CVE-2010-1440" ref_url="http://linux.oracle.com/cve/CVE-2010-1440.html" source="CVE"/>
        <description>Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:07.956-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:28.061-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:40.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23168 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:35.310-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:55.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:103926"/>
          <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:103793"/>
          <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:102982"/>
          <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:103017"/>
          <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:103466"/>
          <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:103742"/>
          <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:103919"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23167" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0451: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference ref_id="ELSA-2012:0451-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0451.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0060" ref_url="http://linux.oracle.com/cve/CVE-2012-0060.html" source="CVE"/>
        <reference ref_id="CVE-2012-0061" ref_url="http://linux.oracle.com/cve/CVE-2012-0061.html" source="CVE"/>
        <reference ref_id="CVE-2012-0815" ref_url="http://linux.oracle.com/cve/CVE-2012-0815.html" source="CVE"/>
        <description>The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:00.652-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:27.758-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:40.526-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23167 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:24.663-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:35.111-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:14:20.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:14:20.906-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:106056"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:105907"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:105977"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:105794"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:105830"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:105795"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:105885"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:105958"/>
            <criterion comment="rpm is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:105348"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:105717"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:105842"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:105889"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:105678"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:105997"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23166" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0594: kernel security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0594-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0594.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3400" ref_url="http://linux.oracle.com/cve/CVE-2012-3400.html" source="CVE"/>
        <description>Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted UDF filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:54.061-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:27.638-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:40.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23166 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:24.779-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:34.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:107158"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:107232"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:107198"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:106848"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:107221"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:107039"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:106432"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:106814"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:106313"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:106991"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:106424"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.2.1.el5" test_ref="oval:org.mitre.oval:tst:107185"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23165" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0870: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference ref_id="ELSA-2013:0870-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0870.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1976" ref_url="http://linux.oracle.com/cve/CVE-2013-1976.html" source="CVE"/>
        <description>The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:54.530-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:27.546-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:40.256-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23165 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:21.536-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:34.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107389"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:106570"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107516"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107520"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:106955"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107562"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107343"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107358"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107511"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107169"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.40.el5_9" test_ref="oval:org.mitre.oval:tst:107505"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23164" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0533: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2012:0533-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0533.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2111" ref_url="http://linux.oracle.com/cve/CVE-2012-2111.html" source="CVE"/>
        <description>The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:30.462-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:27.397-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:40.045-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23164 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.202-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:34.718-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:13:10.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:13:10.215-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:110098"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:110049"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:109652"/>
            <criterion comment="samba3x is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:110086"/>
            <criterion comment="samba3x-client is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:109952"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:110195"/>
            <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:109817"/>
            <criterion comment="samba3x-common is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:109707"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110158"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:109517"/>
            <criterion comment="samba is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:109999"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110146"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110041"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110094"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110127"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110213"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110174"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:109711"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110010"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:110110"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23163" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0549: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0549-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0549.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0887" ref_url="http://linux.oracle.com/cve/CVE-2010-0887.html" source="CVE"/>
        <description>Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:04.904-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:27.279-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:39.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23163 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:21.632-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:34.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104120"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104122"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104167"/>
          <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103952"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103243"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104033"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104114"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.8.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104225"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23162" version="86" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1350: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1350-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1350.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1956" ref_url="http://linux.oracle.com/cve/CVE-2012-1956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3982" ref_url="http://linux.oracle.com/cve/CVE-2012-3982.html" source="CVE"/>
        <reference ref_id="CVE-2012-3986" ref_url="http://linux.oracle.com/cve/CVE-2012-3986.html" source="CVE"/>
        <reference ref_id="CVE-2012-3988" ref_url="http://linux.oracle.com/cve/CVE-2012-3988.html" source="CVE"/>
        <reference ref_id="CVE-2012-3990" ref_url="http://linux.oracle.com/cve/CVE-2012-3990.html" source="CVE"/>
        <reference ref_id="CVE-2012-3991" ref_url="http://linux.oracle.com/cve/CVE-2012-3991.html" source="CVE"/>
        <reference ref_id="CVE-2012-3992" ref_url="http://linux.oracle.com/cve/CVE-2012-3992.html" source="CVE"/>
        <reference ref_id="CVE-2012-3993" ref_url="http://linux.oracle.com/cve/CVE-2012-3993.html" source="CVE"/>
        <reference ref_id="CVE-2012-3994" ref_url="http://linux.oracle.com/cve/CVE-2012-3994.html" source="CVE"/>
        <reference ref_id="CVE-2012-3995" ref_url="http://linux.oracle.com/cve/CVE-2012-3995.html" source="CVE"/>
        <reference ref_id="CVE-2012-4179" ref_url="http://linux.oracle.com/cve/CVE-2012-4179.html" source="CVE"/>
        <reference ref_id="CVE-2012-4180" ref_url="http://linux.oracle.com/cve/CVE-2012-4180.html" source="CVE"/>
        <reference ref_id="CVE-2012-4181" ref_url="http://linux.oracle.com/cve/CVE-2012-4181.html" source="CVE"/>
        <reference ref_id="CVE-2012-4182" ref_url="http://linux.oracle.com/cve/CVE-2012-4182.html" source="CVE"/>
        <reference ref_id="CVE-2012-4183" ref_url="http://linux.oracle.com/cve/CVE-2012-4183.html" source="CVE"/>
        <reference ref_id="CVE-2012-4184" ref_url="http://linux.oracle.com/cve/CVE-2012-4184.html" source="CVE"/>
        <reference ref_id="CVE-2012-4185" ref_url="http://linux.oracle.com/cve/CVE-2012-4185.html" source="CVE"/>
        <reference ref_id="CVE-2012-4186" ref_url="http://linux.oracle.com/cve/CVE-2012-4186.html" source="CVE"/>
        <reference ref_id="CVE-2012-4187" ref_url="http://linux.oracle.com/cve/CVE-2012-4187.html" source="CVE"/>
        <reference ref_id="CVE-2012-4188" ref_url="http://linux.oracle.com/cve/CVE-2012-4188.html" source="CVE"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:45.544-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:26.824-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:39.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23162 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.520-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:34.037-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:11:35.394-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:11:35.394-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:106883"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:106484"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:106496"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:106946"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:106718"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:106648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23161" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0611: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2013:0611-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0611.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1821" ref_url="http://linux.oracle.com/cve/CVE-2013-1821.html" source="CVE"/>
        <description>lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:43.630-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:26.748-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:38.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23161 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:24.537-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:33.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby-devel is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:106936"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:107187"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:107103"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:107307"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:106559"/>
          <criterion comment="ruby is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:107204"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:107275"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:107019"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-29.el5_9" test_ref="oval:org.mitre.oval:tst:107038"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23160" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0780: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2010:0780-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0780.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3176" ref_url="http://linux.oracle.com/cve/CVE-2010-3176.html" source="CVE"/>
        <reference ref_id="CVE-2010-3180" ref_url="http://linux.oracle.com/cve/CVE-2010-3180.html" source="CVE"/>
        <reference ref_id="CVE-2010-3182" ref_url="http://linux.oracle.com/cve/CVE-2010-3182.html" source="CVE"/>
        <description>A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:33.285-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:26.696-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:38.846-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23160 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:24.872-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:33.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-9.el5" test_ref="oval:org.mitre.oval:tst:104304"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23159" version="25" class="patch">
      <metadata>
        <title>ELSA-2011:0909: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2011:0909-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0909.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4492" ref_url="http://linux.oracle.com/cve/CVE-2009-4492.html" source="CVE"/>
        <reference ref_id="CVE-2010-0541" ref_url="http://linux.oracle.com/cve/CVE-2010-0541.html" source="CVE"/>
        <reference ref_id="CVE-2011-0188" ref_url="http://linux.oracle.com/cve/CVE-2011-0188.html" source="CVE"/>
        <reference ref_id="CVE-2011-1004" ref_url="http://linux.oracle.com/cve/CVE-2011-1004.html" source="CVE"/>
        <reference ref_id="CVE-2011-1005" ref_url="http://linux.oracle.com/cve/CVE-2011-1005.html" source="CVE"/>
        <description>The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:15.112-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:26.527-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:38.567-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23159 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:24.190-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:33.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby-docs is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:105008"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104825"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104947"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104621"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104754"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104821"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104900"/>
          <criterion comment="ruby is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104887"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-19.el5_6.1" test_ref="oval:org.mitre.oval:tst:104965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23158" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0411: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openoffice.org</product>
        </affected>
        <reference ref_id="ELSA-2012:0411-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0411.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0037" ref_url="http://linux.oracle.com/cve/CVE-2012-0037.html" source="CVE"/>
        <description>Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:53.163-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:26.301-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:38.160-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23158 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:20.987-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:33.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106018"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105956"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105635"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106014"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105982"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105824"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105758"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105855"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105622"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105707"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105419"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105515"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105705"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105815"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106013"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106057"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105667"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105968"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105945"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105613"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105917"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106051"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105788"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105770"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105119"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105549"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105585"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106025"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105989"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105245"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105178"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106011"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105762"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105732"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105487"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105966"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105066"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105926"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106015"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105932"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106064"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105512"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106062"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105896"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105860"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105811"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105563"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105331"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105664"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105617"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105828"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105771"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105914"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105590"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106007"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106021"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105971"/>
          <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105599"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106050"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105898"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105710"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105941"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:106042"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105853"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105882"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105924"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105687"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105420"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105388"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105826"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105912"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105730"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105928"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105851"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105919"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105341"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105768"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.1" test_ref="oval:org.mitre.oval:tst:105480"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23157" version="73" class="patch">
      <metadata>
        <title>ELSA-2012:0034: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:0034-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0034.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3389" ref_url="http://linux.oracle.com/cve/CVE-2011-3389.html" source="CVE"/>
        <reference ref_id="CVE-2011-3516" ref_url="http://linux.oracle.com/cve/CVE-2011-3516.html" source="CVE"/>
        <reference ref_id="CVE-2011-3521" ref_url="http://linux.oracle.com/cve/CVE-2011-3521.html" source="CVE"/>
        <reference ref_id="CVE-2011-3544" ref_url="http://linux.oracle.com/cve/CVE-2011-3544.html" source="CVE"/>
        <reference ref_id="CVE-2011-3545" ref_url="http://linux.oracle.com/cve/CVE-2011-3545.html" source="CVE"/>
        <reference ref_id="CVE-2011-3546" ref_url="http://linux.oracle.com/cve/CVE-2011-3546.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3549" ref_url="http://linux.oracle.com/cve/CVE-2011-3549.html" source="CVE"/>
        <reference ref_id="CVE-2011-3550" ref_url="http://linux.oracle.com/cve/CVE-2011-3550.html" source="CVE"/>
        <reference ref_id="CVE-2011-3551" ref_url="http://linux.oracle.com/cve/CVE-2011-3551.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3553" ref_url="http://linux.oracle.com/cve/CVE-2011-3553.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <reference ref_id="CVE-2011-3557" ref_url="http://linux.oracle.com/cve/CVE-2011-3557.html" source="CVE"/>
        <reference ref_id="CVE-2011-3560" ref_url="http://linux.oracle.com/cve/CVE-2011-3560.html" source="CVE"/>
        <reference ref_id="CVE-2011-3561" ref_url="http://linux.oracle.com/cve/CVE-2011-3561.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:05.950-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:25.801-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:37.994-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23157 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:26.070-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:32.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105712"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105503"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105019"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105312"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105706"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105483"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105714"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:105604"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:105709"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:105734"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:105726"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:105274"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:104763"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:105643"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:105472"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23156" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:0095: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference ref_id="ELSA-2012:0095-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0095.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3743" ref_url="http://linux.oracle.com/cve/CVE-2009-3743.html" source="CVE"/>
        <reference ref_id="CVE-2010-2055" ref_url="http://linux.oracle.com/cve/CVE-2010-2055.html" source="CVE"/>
        <reference ref_id="CVE-2010-4054" ref_url="http://linux.oracle.com/cve/CVE-2010-4054.html" source="CVE"/>
        <reference ref_id="CVE-2010-4820" ref_url="http://linux.oracle.com/cve/CVE-2010-4820.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:03.677-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:25.675-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:37.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23156 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.787-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:32.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:105607"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:105393"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:105358"/>
            <criterion comment="ghostscript is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:105737"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:105748"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:105739"/>
            <criterion comment="ghostscript is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:105534"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23155" version="21" class="patch">
      <metadata>
        <title>ELSA-2010:0819: pam security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pam</product>
        </affected>
        <reference ref_id="ELSA-2010:0819-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0819.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3316" ref_url="http://linux.oracle.com/cve/CVE-2010-3316.html" source="CVE"/>
        <reference ref_id="CVE-2010-3435" ref_url="http://linux.oracle.com/cve/CVE-2010-3435.html" source="CVE"/>
        <reference ref_id="CVE-2010-3853" ref_url="http://linux.oracle.com/cve/CVE-2010-3853.html" source="CVE"/>
        <reference ref_id="CVE-2010-4707" ref_url="http://linux.oracle.com/cve/CVE-2010-4707.html" source="CVE"/>
        <description>The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:34.483-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:25.517-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:37.647-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23155 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:24.093-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:32.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pam-devel is earlier than 0:0.99.6.2-6.el5_5.2" test_ref="oval:org.mitre.oval:tst:103925"/>
          <criterion comment="pam is earlier than 0:0.99.6.2-6.el5_5.2" test_ref="oval:org.mitre.oval:tst:104395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23154" version="45" class="patch">
      <metadata>
        <title>ELSA-2010:0782: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>nss</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2010:0782-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0782.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3170" ref_url="http://linux.oracle.com/cve/CVE-2010-3170.html" source="CVE"/>
        <reference ref_id="CVE-2010-3173" ref_url="http://linux.oracle.com/cve/CVE-2010-3173.html" source="CVE"/>
        <reference ref_id="CVE-2010-3175" ref_url="http://linux.oracle.com/cve/CVE-2010-3175.html" source="CVE"/>
        <reference ref_id="CVE-2010-3176" ref_url="http://linux.oracle.com/cve/CVE-2010-3176.html" source="CVE"/>
        <reference ref_id="CVE-2010-3177" ref_url="http://linux.oracle.com/cve/CVE-2010-3177.html" source="CVE"/>
        <reference ref_id="CVE-2010-3178" ref_url="http://linux.oracle.com/cve/CVE-2010-3178.html" source="CVE"/>
        <reference ref_id="CVE-2010-3179" ref_url="http://linux.oracle.com/cve/CVE-2010-3179.html" source="CVE"/>
        <reference ref_id="CVE-2010-3180" ref_url="http://linux.oracle.com/cve/CVE-2010-3180.html" source="CVE"/>
        <reference ref_id="CVE-2010-3182" ref_url="http://linux.oracle.com/cve/CVE-2010-3182.html" source="CVE"/>
        <reference ref_id="CVE-2010-3183" ref_url="http://linux.oracle.com/cve/CVE-2010-3183.html" source="CVE"/>
        <description>The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:17.168-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:25.212-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:37.173-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23154 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.065-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:32.023-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xulrunner is earlier than 0:1.9.2.11-2.el5" test_ref="oval:org.mitre.oval:tst:104393"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.11-2.el5" test_ref="oval:org.mitre.oval:tst:104273"/>
          <criterion comment="firefox is earlier than 0:3.6.11-2.el5" test_ref="oval:org.mitre.oval:tst:104316"/>
          <criterion comment="nss is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:104104"/>
          <criterion comment="nss-tools is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:104431"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:103766"/>
          <criterion comment="nss-devel is earlier than 0:3.12.8-1.el5" test_ref="oval:org.mitre.oval:tst:103444"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23153" version="26" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0272: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0272-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0272.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0775" ref_url="http://linux.oracle.com/cve/CVE-2013-0775.html" source="CVE"/>
        <reference ref_id="CVE-2013-0776" ref_url="http://linux.oracle.com/cve/CVE-2013-0776.html" source="CVE"/>
        <reference ref_id="CVE-2013-0780" ref_url="http://linux.oracle.com/cve/CVE-2013-0780.html" source="CVE"/>
        <reference ref_id="CVE-2013-0782" ref_url="http://linux.oracle.com/cve/CVE-2013-0782.html" source="CVE"/>
        <reference ref_id="CVE-2013-0783" ref_url="http://linux.oracle.com/cve/CVE-2013-0783.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:01.385-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:25.083-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:37.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23153 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.659-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:31.926-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:10:52.541-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:10:52.541-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:106756"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:106927"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23151" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0449: rhn-client-tools security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>rhn-client-tools</product>
        </affected>
        <reference ref_id="ELSA-2010:0449-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0449.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1439" ref_url="http://linux.oracle.com/cve/CVE-2010-1439.html" source="CVE"/>
        <description>yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:00.245-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:24.858-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:36.879-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23151 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.843-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:31.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="rhn-check is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:103911"/>
          <criterion comment="rhn-setup-gnome is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:104002"/>
          <criterion comment="rhn-client-tools is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:103901"/>
          <criterion comment="rhn-setup is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:103883"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23150" version="33" class="patch">
      <metadata>
        <title>ELSA-2011:0370: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2011:0370-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0370.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3445" ref_url="http://linux.oracle.com/cve/CVE-2010-3445.html" source="CVE"/>
        <reference ref_id="CVE-2011-0024" ref_url="http://linux.oracle.com/cve/CVE-2011-0024.html" source="CVE"/>
        <reference ref_id="CVE-2011-0538" ref_url="http://linux.oracle.com/cve/CVE-2011-0538.html" source="CVE"/>
        <reference ref_id="CVE-2011-1139" ref_url="http://linux.oracle.com/cve/CVE-2011-1139.html" source="CVE"/>
        <reference ref_id="CVE-2011-1140" ref_url="http://linux.oracle.com/cve/CVE-2011-1140.html" source="CVE"/>
        <reference ref_id="CVE-2011-1141" ref_url="http://linux.oracle.com/cve/CVE-2011-1141.html" source="CVE"/>
        <reference ref_id="CVE-2011-1143" ref_url="http://linux.oracle.com/cve/CVE-2011-1143.html" source="CVE"/>
        <description>epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:08.402-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:24.695-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:36.540-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23150 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.029-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:31.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="wireshark is earlier than 0:1.0.15-1.el5_6.4" test_ref="oval:org.mitre.oval:tst:104664"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_6.4" test_ref="oval:org.mitre.oval:tst:104660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23149" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:1292: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1292-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1292.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3511" ref_url="http://linux.oracle.com/cve/CVE-2012-3511.html" source="CVE"/>
        <reference ref_id="CVE-2013-2141" ref_url="http://linux.oracle.com/cve/CVE-2013-2141.html" source="CVE"/>
        <reference ref_id="CVE-2013-4162" ref_url="http://linux.oracle.com/cve/CVE-2013-4162.html" source="CVE"/>
        <description>The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:32.420-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:24.590-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:36.328-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23149 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.666-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:31.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107695"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107614"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107553"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107617"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107651"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107635"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107642"/>
          <criterion comment="kernel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107273"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107507"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107624"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107509"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-348.18.1.el5" test_ref="oval:org.mitre.oval:tst:107785"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23148" version="66" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1483: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1483-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1483.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4201" ref_url="http://linux.oracle.com/cve/CVE-2012-4201.html" source="CVE"/>
        <reference ref_id="CVE-2012-4202" ref_url="http://linux.oracle.com/cve/CVE-2012-4202.html" source="CVE"/>
        <reference ref_id="CVE-2012-4207" ref_url="http://linux.oracle.com/cve/CVE-2012-4207.html" source="CVE"/>
        <reference ref_id="CVE-2012-4209" ref_url="http://linux.oracle.com/cve/CVE-2012-4209.html" source="CVE"/>
        <reference ref_id="CVE-2012-4214" ref_url="http://linux.oracle.com/cve/CVE-2012-4214.html" source="CVE"/>
        <reference ref_id="CVE-2012-4215" ref_url="http://linux.oracle.com/cve/CVE-2012-4215.html" source="CVE"/>
        <reference ref_id="CVE-2012-4216" ref_url="http://linux.oracle.com/cve/CVE-2012-4216.html" source="CVE"/>
        <reference ref_id="CVE-2012-5829" ref_url="http://linux.oracle.com/cve/CVE-2012-5829.html" source="CVE"/>
        <reference ref_id="CVE-2012-5830" ref_url="http://linux.oracle.com/cve/CVE-2012-5830.html" source="CVE"/>
        <reference ref_id="CVE-2012-5833" ref_url="http://linux.oracle.com/cve/CVE-2012-5833.html" source="CVE"/>
        <reference ref_id="CVE-2012-5835" ref_url="http://linux.oracle.com/cve/CVE-2012-5835.html" source="CVE"/>
        <reference ref_id="CVE-2012-5839" ref_url="http://linux.oracle.com/cve/CVE-2012-5839.html" source="CVE"/>
        <reference ref_id="CVE-2012-5840" ref_url="http://linux.oracle.com/cve/CVE-2012-5840.html" source="CVE"/>
        <reference ref_id="CVE-2012-5841" ref_url="http://linux.oracle.com/cve/CVE-2012-5841.html" source="CVE"/>
        <reference ref_id="CVE-2012-5842" ref_url="http://linux.oracle.com/cve/CVE-2012-5842.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:46.577-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:24.208-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:35.713-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23148 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.907-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:30.873-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:10:21.074-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:10:21.074-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:107052"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:106794"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23147" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0129: ruby security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2013:0129-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0129.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4481" ref_url="http://linux.oracle.com/cve/CVE-2012-4481.html" source="CVE"/>
        <reference ref_id="CVE-2012-4522" ref_url="http://linux.oracle.com/cve/CVE-2012-4522.html" source="CVE"/>
        <description>The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:54.385-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:24.076-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:35.549-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23147 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.996-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:30.753-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby-tcltk is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:106835"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:106964"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:107042"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:107071"/>
          <criterion comment="ruby-mode is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:106622"/>
          <criterion comment="ruby is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:106938"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:106813"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:106868"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.5-27.el5" test_ref="oval:org.mitre.oval:tst:106682"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23146" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0216: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2013:0216-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0216.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5669" ref_url="http://linux.oracle.com/cve/CVE-2012-5669.html" source="CVE"/>
        <description>The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:05.225-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:23.995-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:35.430-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23146 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:20.503-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:30.649-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:09:50.842-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:09:50.842-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:107068"/>
            <criterion comment="freetype is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:107086"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:106348"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:107093"/>
            <criterion comment="freetype is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:107128"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:106668"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23145" version="33" class="patch">
      <metadata>
        <title>ELSA-2010:0723: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0723-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0723.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1083" ref_url="http://linux.oracle.com/cve/CVE-2010-1083.html" source="CVE"/>
        <reference ref_id="CVE-2010-2492" ref_url="http://linux.oracle.com/cve/CVE-2010-2492.html" source="CVE"/>
        <reference ref_id="CVE-2010-2798" ref_url="http://linux.oracle.com/cve/CVE-2010-2798.html" source="CVE"/>
        <reference ref_id="CVE-2010-2938" ref_url="http://linux.oracle.com/cve/CVE-2010-2938.html" source="CVE"/>
        <reference ref_id="CVE-2010-2942" ref_url="http://linux.oracle.com/cve/CVE-2010-2942.html" source="CVE"/>
        <reference ref_id="CVE-2010-2943" ref_url="http://linux.oracle.com/cve/CVE-2010-2943.html" source="CVE"/>
        <reference ref_id="CVE-2010-3015" ref_url="http://linux.oracle.com/cve/CVE-2010-3015.html" source="CVE"/>
        <description>Integer overflow in the ext4_ext_get_blocks function in fs/ext4/extents.c in the Linux kernel before 2.6.34 allows local users to cause a denial of service (BUG and system crash) via a write operation on the last block of a large file, followed by a sync operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:23.198-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:23.818-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:35.099-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23145 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:21.421-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:30.384-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104137"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104313"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104376"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:103944"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104368"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104341"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104300"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104264"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104053"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104310"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:103879"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.17.1.el5" test_ref="oval:org.mitre.oval:tst:104009"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23144" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0976: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2010:0976-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0976.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3613" ref_url="http://linux.oracle.com/cve/CVE-2010-3613.html" source="CVE"/>
        <reference ref_id="CVE-2010-3614" ref_url="http://linux.oracle.com/cve/CVE-2010-3614.html" source="CVE"/>
        <reference ref_id="CVE-2010-3762" ref_url="http://linux.oracle.com/cve/CVE-2010-3762.html" source="CVE"/>
        <description>ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:26.474-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:23.645-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:34.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23144 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:20.696-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:30.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104614"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104357"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104262"/>
          <criterion comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104477"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104418"/>
          <criterion comment="bind is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104335"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104471"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_5.3" test_ref="oval:org.mitre.oval:tst:104165"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23143" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0466: samba3x security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference ref_id="ELSA-2012:0466-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0466.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1182" ref_url="http://linux.oracle.com/cve/CVE-2012-1182.html" source="CVE"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:53.476-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:23.569-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:34.759-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23143 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.896-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:30.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="samba3x-common is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:105467"/>
          <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:105878"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:105940"/>
          <criterion comment="samba3x-client is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:105496"/>
          <criterion comment="samba3x is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:105484"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:106036"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:105740"/>
          <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.108.el5_8" test_ref="oval:org.mitre.oval:tst:105881"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23142" version="74" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1088: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1088-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1088.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1948" ref_url="http://linux.oracle.com/cve/CVE-2012-1948.html" source="CVE"/>
        <reference ref_id="CVE-2012-1950" ref_url="http://linux.oracle.com/cve/CVE-2012-1950.html" source="CVE"/>
        <reference ref_id="CVE-2012-1951" ref_url="http://linux.oracle.com/cve/CVE-2012-1951.html" source="CVE"/>
        <reference ref_id="CVE-2012-1952" ref_url="http://linux.oracle.com/cve/CVE-2012-1952.html" source="CVE"/>
        <reference ref_id="CVE-2012-1953" ref_url="http://linux.oracle.com/cve/CVE-2012-1953.html" source="CVE"/>
        <reference ref_id="CVE-2012-1954" ref_url="http://linux.oracle.com/cve/CVE-2012-1954.html" source="CVE"/>
        <reference ref_id="CVE-2012-1955" ref_url="http://linux.oracle.com/cve/CVE-2012-1955.html" source="CVE"/>
        <reference ref_id="CVE-2012-1957" ref_url="http://linux.oracle.com/cve/CVE-2012-1957.html" source="CVE"/>
        <reference ref_id="CVE-2012-1958" ref_url="http://linux.oracle.com/cve/CVE-2012-1958.html" source="CVE"/>
        <reference ref_id="CVE-2012-1959" ref_url="http://linux.oracle.com/cve/CVE-2012-1959.html" source="CVE"/>
        <reference ref_id="CVE-2012-1961" ref_url="http://linux.oracle.com/cve/CVE-2012-1961.html" source="CVE"/>
        <reference ref_id="CVE-2012-1962" ref_url="http://linux.oracle.com/cve/CVE-2012-1962.html" source="CVE"/>
        <reference ref_id="CVE-2012-1963" ref_url="http://linux.oracle.com/cve/CVE-2012-1963.html" source="CVE"/>
        <reference ref_id="CVE-2012-1964" ref_url="http://linux.oracle.com/cve/CVE-2012-1964.html" source="CVE"/>
        <reference ref_id="CVE-2012-1965" ref_url="http://linux.oracle.com/cve/CVE-2012-1965.html" source="CVE"/>
        <reference ref_id="CVE-2012-1966" ref_url="http://linux.oracle.com/cve/CVE-2012-1966.html" source="CVE"/>
        <reference ref_id="CVE-2012-1967" ref_url="http://linux.oracle.com/cve/CVE-2012-1967.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:21:55.551-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:23.178-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:34.067-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23142 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.246-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:29.515-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:09:03.439-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:09:03.439-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:106677"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:106343"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:106491"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:105841"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:106390"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:106588"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23141" version="41" class="patch">
      <metadata>
        <title>ELSA-2010:0489: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0489-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0489.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0840" ref_url="http://linux.oracle.com/cve/CVE-2010-0840.html" source="CVE"/>
        <reference ref_id="CVE-2010-0841" ref_url="http://linux.oracle.com/cve/CVE-2010-0841.html" source="CVE"/>
        <reference ref_id="CVE-2010-0842" ref_url="http://linux.oracle.com/cve/CVE-2010-0842.html" source="CVE"/>
        <reference ref_id="CVE-2010-0843" ref_url="http://linux.oracle.com/cve/CVE-2010-0843.html" source="CVE"/>
        <reference ref_id="CVE-2010-0844" ref_url="http://linux.oracle.com/cve/CVE-2010-0844.html" source="CVE"/>
        <reference ref_id="CVE-2010-0846" ref_url="http://linux.oracle.com/cve/CVE-2010-0846.html" source="CVE"/>
        <reference ref_id="CVE-2010-0847" ref_url="http://linux.oracle.com/cve/CVE-2010-0847.html" source="CVE"/>
        <reference ref_id="CVE-2010-0848" ref_url="http://linux.oracle.com/cve/CVE-2010-0848.html" source="CVE"/>
        <reference ref_id="CVE-2010-0849" ref_url="http://linux.oracle.com/cve/CVE-2010-0849.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.	NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:59.166-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:22.940-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:33.966-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23141 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.159-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:29.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104062"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103920"/>
          <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103921"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103414"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103759"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103840"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103103"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.11.2-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23139" version="34" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0469: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2012:0469-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0469.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4370" ref_url="http://linux.oracle.com/cve/CVE-2011-4370.html" source="CVE"/>
        <reference ref_id="CVE-2011-4371" ref_url="http://linux.oracle.com/cve/CVE-2011-4371.html" source="CVE"/>
        <reference ref_id="CVE-2011-4372" ref_url="http://linux.oracle.com/cve/CVE-2011-4372.html" source="CVE"/>
        <reference ref_id="CVE-2011-4373" ref_url="http://linux.oracle.com/cve/CVE-2011-4373.html" source="CVE"/>
        <reference ref_id="CVE-2012-0774" ref_url="http://linux.oracle.com/cve/CVE-2012-0774.html" source="CVE"/>
        <reference ref_id="CVE-2012-0775" ref_url="http://linux.oracle.com/cve/CVE-2012-0775.html" source="CVE"/>
        <reference ref_id="CVE-2012-0777" ref_url="http://linux.oracle.com/cve/CVE-2012-0777.html" source="CVE"/>
        <description>The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:58.423-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:22.650-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:33.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23139 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.480-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:29.059-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:08:20.053-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:08:20.053-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:105641"/>
            <criterion comment="acroread is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:105850"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:105864"/>
            <criterion comment="acroread is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:105661"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23138" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0703: bzip2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bzip2</product>
        </affected>
        <reference ref_id="ELSA-2010:0703-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0703.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0405" ref_url="http://linux.oracle.com/cve/CVE-2010-0405.html" source="CVE"/>
        <description>Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:32.615-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:22.587-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:33.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23138 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:21.714-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:28.980-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bzip2-devel is earlier than 0:1.0.3-6.el5_5" test_ref="oval:org.mitre.oval:tst:103782"/>
          <criterion comment="bzip2-libs is earlier than 0:1.0.3-6.el5_5" test_ref="oval:org.mitre.oval:tst:103905"/>
          <criterion comment="bzip2 is earlier than 0:1.0.3-6.el5_5" test_ref="oval:org.mitre.oval:tst:104260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23137" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0407: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference ref_id="ELSA-2012:0407-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0407.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3045" ref_url="http://linux.oracle.com/cve/CVE-2011-3045.html" source="CVE"/>
        <description>Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:51.937-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:22.507-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:33.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23137 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:20.603-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:28.858-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:07:40.862-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:07:40.862-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:105535"/>
            <criterion comment="libpng is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:105486"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-static is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:105964"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:105551"/>
            <criterion comment="libpng is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:105894"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23136" version="46" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0982: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0982-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0982.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1682" ref_url="http://linux.oracle.com/cve/CVE-2013-1682.html" source="CVE"/>
        <reference ref_id="CVE-2013-1684" ref_url="http://linux.oracle.com/cve/CVE-2013-1684.html" source="CVE"/>
        <reference ref_id="CVE-2013-1685" ref_url="http://linux.oracle.com/cve/CVE-2013-1685.html" source="CVE"/>
        <reference ref_id="CVE-2013-1686" ref_url="http://linux.oracle.com/cve/CVE-2013-1686.html" source="CVE"/>
        <reference ref_id="CVE-2013-1687" ref_url="http://linux.oracle.com/cve/CVE-2013-1687.html" source="CVE"/>
        <reference ref_id="CVE-2013-1690" ref_url="http://linux.oracle.com/cve/CVE-2013-1690.html" source="CVE"/>
        <reference ref_id="CVE-2013-1692" ref_url="http://linux.oracle.com/cve/CVE-2013-1692.html" source="CVE"/>
        <reference ref_id="CVE-2013-1693" ref_url="http://linux.oracle.com/cve/CVE-2013-1693.html" source="CVE"/>
        <reference ref_id="CVE-2013-1694" ref_url="http://linux.oracle.com/cve/CVE-2013-1694.html" source="CVE"/>
        <reference ref_id="CVE-2013-1697" ref_url="http://linux.oracle.com/cve/CVE-2013-1697.html" source="CVE"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:11.012-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:22.276-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:32.839-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23136 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.781-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:28.530-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:07:00.333-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:07:00.333-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:112045"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:112171"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23135" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0827: openswan security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2013:0827-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0827.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2053" ref_url="http://linux.oracle.com/cve/CVE-2013-2053.html" source="CVE"/>
        <description>Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.	 NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:44.323-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:22.211-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:32.682-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23135 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.361-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:28.437-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:06:30.434-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:06:30.434-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:107498"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:107414"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:107531"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:107151"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23134" version="37" class="patch">
      <metadata>
        <title>ELSA-2012:1047: php53 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference ref_id="ELSA-2012:1047-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1047.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2950" ref_url="http://linux.oracle.com/cve/CVE-2010-2950.html" source="CVE"/>
        <reference ref_id="CVE-2011-4153" ref_url="http://linux.oracle.com/cve/CVE-2011-4153.html" source="CVE"/>
        <reference ref_id="CVE-2012-0057" ref_url="http://linux.oracle.com/cve/CVE-2012-0057.html" source="CVE"/>
        <reference ref_id="CVE-2012-0789" ref_url="http://linux.oracle.com/cve/CVE-2012-0789.html" source="CVE"/>
        <reference ref_id="CVE-2012-1172" ref_url="http://linux.oracle.com/cve/CVE-2012-1172.html" source="CVE"/>
        <reference ref_id="CVE-2012-2143" ref_url="http://linux.oracle.com/cve/CVE-2012-2143.html" source="CVE"/>
        <reference ref_id="CVE-2012-2336" ref_url="http://linux.oracle.com/cve/CVE-2012-2336.html" source="CVE"/>
        <reference ref_id="CVE-2012-2386" ref_url="http://linux.oracle.com/cve/CVE-2012-2386.html" source="CVE"/>
        <description>Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:20.556-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.986-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:32.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23134 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.531-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:28.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106304"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106680"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106483"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106543"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:105744"/>
          <criterion comment="php53 is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106555"/>
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106641"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106611"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106673"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106529"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106252"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106487"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106731"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106601"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106324"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106301"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106510"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106691"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106520"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106516"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-13.el5_8" test_ref="oval:org.mitre.oval:tst:106108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23132" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0436: avahi security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>avahi</product>
        </affected>
        <reference ref_id="ELSA-2011:0436-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0436.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1002" ref_url="http://linux.oracle.com/cve/CVE-2011-1002.html" source="CVE"/>
        <description>avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:14.233-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.790-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:32.006-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23132 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:21.301-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:27.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104959"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104854"/>
          <criterion comment="avahi is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104743"/>
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104799"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104590"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104863"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104593"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104981"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104643"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104538"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.16-10.el5_6" test_ref="oval:org.mitre.oval:tst:104700"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23131" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0850: flash-plugin security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0850-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0850.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2107" ref_url="http://linux.oracle.com/cve/CVE-2011-2107.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:22.463-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.705-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:31.902-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23131 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:24.368-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:27.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.22-1.el5" test_ref="oval:org.mitre.oval:tst:104922"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.22-1.el6" test_ref="oval:org.mitre.oval:tst:105022"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23130" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0442: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2010:0442-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0442.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1626" ref_url="http://linux.oracle.com/cve/CVE-2010-1626.html" source="CVE"/>
        <reference ref_id="CVE-2010-1848" ref_url="http://linux.oracle.com/cve/CVE-2010-1848.html" source="CVE"/>
        <reference ref_id="CVE-2010-1850" ref_url="http://linux.oracle.com/cve/CVE-2010-1850.html" source="CVE"/>
        <description>Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:56.397-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.586-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:31.727-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23130 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.314-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:27.782-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:103699"/>
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:104030"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:104044"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:103980"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:103991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23129" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0614: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0614-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0614.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0787" ref_url="http://linux.oracle.com/cve/CVE-2013-0787.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:34.391-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.519-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:31.588-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23129 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.751-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:27.677-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:111751"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:111658"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:111571"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:111481"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23128" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1371: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2011:1371-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1371.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1091" ref_url="http://linux.oracle.com/cve/CVE-2011-1091.html" source="CVE"/>
        <reference ref_id="CVE-2011-3594" ref_url="http://linux.oracle.com/cve/CVE-2011-3594.html" source="CVE"/>
        <description>The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:34.024-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.431-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:31.415-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23128 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.270-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:27.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:105287"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:104929"/>
          <criterion comment="finch is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:104980"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:104389"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:105248"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:105372"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:105250"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:105290"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_7.1" test_ref="oval:org.mitre.oval:tst:105164"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23126" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0327: subversion security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference ref_id="ELSA-2011:0327-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0327.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0715" ref_url="http://linux.oracle.com/cve/CVE-2011-0715.html" source="CVE"/>
        <description>The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:05.286-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.276-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:31.180-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23126 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.664-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:27.307-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:104862"/>
          <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:104914"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:104113"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:104838"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:104550"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.3" test_ref="oval:org.mitre.oval:tst:104541"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23125" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0198: postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference ref_id="ELSA-2011:0198-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0198.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4015" ref_url="http://linux.oracle.com/cve/CVE-2010-4015.html" source="CVE"/>
        <description>Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:13.265-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:21.192-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:31.041-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23125 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.375-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:27.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104827"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104427"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104788"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104417"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:103966"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104720"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104392"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104388"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104615"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104259"/>
          <criterion comment="postgresql84 is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104448"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.7-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104782"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23124" version="26" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0271: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
          <product>libproxy</product>
        </affected>
        <reference ref_id="ELSA-2013:0271-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0271.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0775" ref_url="http://linux.oracle.com/cve/CVE-2013-0775.html" source="CVE"/>
        <reference ref_id="CVE-2013-0776" ref_url="http://linux.oracle.com/cve/CVE-2013-0776.html" source="CVE"/>
        <reference ref_id="CVE-2013-0780" ref_url="http://linux.oracle.com/cve/CVE-2013-0780.html" source="CVE"/>
        <reference ref_id="CVE-2013-0782" ref_url="http://linux.oracle.com/cve/CVE-2013-0782.html" source="CVE"/>
        <reference ref_id="CVE-2013-0783" ref_url="http://linux.oracle.com/cve/CVE-2013-0783.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:02.955-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:20.994-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:30.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23124 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:21.825-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:26.934-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:05:52.362-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:05:52.362-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="yelp is earlier than 0:2.28.1-17.el6_3" test_ref="oval:org.mitre.oval:tst:106933"/>
            <criterion comment="libproxy-bin is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:106685"/>
            <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:106352"/>
            <criterion comment="libproxy-devel is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:106864"/>
            <criterion comment="libproxy-webkit is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:106180"/>
            <criterion comment="libproxy is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:106845"/>
            <criterion comment="libproxy-gnome is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:107119"/>
            <criterion comment="libproxy-python is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:107133"/>
            <criterion comment="libproxy-kde is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:106984"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:107088"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:107043"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:106859"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:106859"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="yelp is earlier than 0:2.16.0-30.el5_9" test_ref="oval:org.mitre.oval:tst:106220"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:107112"/>
            <criterion comment="devhelp is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:107004"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:107153"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:106537"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:107090"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23123" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0152: kexec-tools security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kexec-tools</product>
        </affected>
        <reference ref_id="ELSA-2012:0152-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0152.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3588" ref_url="http://linux.oracle.com/cve/CVE-2011-3588.html" source="CVE"/>
        <reference ref_id="CVE-2011-3589" ref_url="http://linux.oracle.com/cve/CVE-2011-3589.html" source="CVE"/>
        <reference ref_id="CVE-2011-3590" ref_url="http://linux.oracle.com/cve/CVE-2011-3590.html" source="CVE"/>
        <description>The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:07.931-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:20.874-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:30.556-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23123 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:26.192-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:26.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="kexec-tools is earlier than 0:1.102pre-154.el5" test_ref="oval:org.mitre.oval:tst:105859"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23122" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0841: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2011:0841-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0841.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1769" ref_url="http://linux.oracle.com/cve/CVE-2011-1769.html" source="CVE"/>
        <description>SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs context variable access.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:19.022-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:20.776-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:30.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23122 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.578-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:26.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="systemtap-testsuite is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:104934"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:104885"/>
          <criterion comment="systemtap is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:104901"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:104656"/>
          <criterion comment="systemtap-client is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:104993"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:104938"/>
          <criterion comment="systemtap-server is earlier than 0:1.3-4.el5_6.1" test_ref="oval:org.mitre.oval:tst:104996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23121" version="33" class="patch">
      <metadata>
        <title>ELSA-2010:0682: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2010:0682-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0682.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2760" ref_url="http://linux.oracle.com/cve/CVE-2010-2760.html" source="CVE"/>
        <reference ref_id="CVE-2010-2765" ref_url="http://linux.oracle.com/cve/CVE-2010-2765.html" source="CVE"/>
        <reference ref_id="CVE-2010-2767" ref_url="http://linux.oracle.com/cve/CVE-2010-2767.html" source="CVE"/>
        <reference ref_id="CVE-2010-2768" ref_url="http://linux.oracle.com/cve/CVE-2010-2768.html" source="CVE"/>
        <reference ref_id="CVE-2010-3167" ref_url="http://linux.oracle.com/cve/CVE-2010-3167.html" source="CVE"/>
        <reference ref_id="CVE-2010-3168" ref_url="http://linux.oracle.com/cve/CVE-2010-3168.html" source="CVE"/>
        <reference ref_id="CVE-2010-3169" ref_url="http://linux.oracle.com/cve/CVE-2010-3169.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:20.947-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:20.607-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:30.086-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23121 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:23.122-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:26.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-8.el5" test_ref="oval:org.mitre.oval:tst:104254"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23120" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0706: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2010:0706-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0706.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2884" ref_url="http://linux.oracle.com/cve/CVE-2010-2884.html" source="CVE"/>
        <description>Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in September 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:24.349-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:20.537-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:29.963-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23120 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:22.395-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:26.328-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="flash-plugin is earlier than 0:10.1.85.3-1.el5" test_ref="oval:org.mitre.oval:tst:103869"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23119" version="78" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1384: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2011:1384-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1384.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3389" ref_url="http://linux.oracle.com/cve/CVE-2011-3389.html" source="CVE"/>
        <reference ref_id="CVE-2011-3516" ref_url="http://linux.oracle.com/cve/CVE-2011-3516.html" source="CVE"/>
        <reference ref_id="CVE-2011-3521" ref_url="http://linux.oracle.com/cve/CVE-2011-3521.html" source="CVE"/>
        <reference ref_id="CVE-2011-3544" ref_url="http://linux.oracle.com/cve/CVE-2011-3544.html" source="CVE"/>
        <reference ref_id="CVE-2011-3545" ref_url="http://linux.oracle.com/cve/CVE-2011-3545.html" source="CVE"/>
        <reference ref_id="CVE-2011-3546" ref_url="http://linux.oracle.com/cve/CVE-2011-3546.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3549" ref_url="http://linux.oracle.com/cve/CVE-2011-3549.html" source="CVE"/>
        <reference ref_id="CVE-2011-3550" ref_url="http://linux.oracle.com/cve/CVE-2011-3550.html" source="CVE"/>
        <reference ref_id="CVE-2011-3551" ref_url="http://linux.oracle.com/cve/CVE-2011-3551.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3553" ref_url="http://linux.oracle.com/cve/CVE-2011-3553.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <reference ref_id="CVE-2011-3557" ref_url="http://linux.oracle.com/cve/CVE-2011-3557.html" source="CVE"/>
        <reference ref_id="CVE-2011-3558" ref_url="http://linux.oracle.com/cve/CVE-2011-3558.html" source="CVE"/>
        <reference ref_id="CVE-2011-3560" ref_url="http://linux.oracle.com/cve/CVE-2011-3560.html" source="CVE"/>
        <reference ref_id="CVE-2011-3561" ref_url="http://linux.oracle.com/cve/CVE-2011-3561.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:28.761-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:20.068-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:29.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23119 - optimisation of Oracle Linux content" date="2014-05-05T17:49:00.090-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:51:25.004-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:25.939-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:04:25.644-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:04:25.644-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105231"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105220"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105036"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105118"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105390"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104933"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105251"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105366"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104998"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104920"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104737"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105328"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23118" version="37" class="patch">
      <metadata>
        <title>ELSA-2012:1201: tetex security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tetex</product>
        </affected>
        <reference ref_id="ELSA-2012:1201-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1201.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2642" ref_url="http://linux.oracle.com/cve/CVE-2010-2642.html" source="CVE"/>
        <reference ref_id="CVE-2010-3702" ref_url="http://linux.oracle.com/cve/CVE-2010-3702.html" source="CVE"/>
        <reference ref_id="CVE-2010-3704" ref_url="http://linux.oracle.com/cve/CVE-2010-3704.html" source="CVE"/>
        <reference ref_id="CVE-2011-0433" ref_url="http://linux.oracle.com/cve/CVE-2011-0433.html" source="CVE"/>
        <reference ref_id="CVE-2011-0764" ref_url="http://linux.oracle.com/cve/CVE-2011-0764.html" source="CVE"/>
        <reference ref_id="CVE-2011-1552" ref_url="http://linux.oracle.com/cve/CVE-2011-1552.html" source="CVE"/>
        <reference ref_id="CVE-2011-1553" ref_url="http://linux.oracle.com/cve/CVE-2011-1553.html" source="CVE"/>
        <reference ref_id="CVE-2011-1554" ref_url="http://linux.oracle.com/cve/CVE-2011-1554.html" source="CVE"/>
        <description>Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:37.058-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:19.877-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:29.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23118 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:20.798-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:55.041-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tetex-latex is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:106774"/>
          <criterion comment="tetex-doc is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:106422"/>
          <criterion comment="tetex is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:106533"/>
          <criterion comment="tetex-xdvi is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:106438"/>
          <criterion comment="tetex-afm is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:106695"/>
          <criterion comment="tetex-dvips is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:106733"/>
          <criterion comment="tetex-fonts is earlier than 0:3.0-33.15.el5_8.1" test_ref="oval:org.mitre.oval:tst:106097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23117" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0975: sssd security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sssd</product>
        </affected>
        <reference ref_id="ELSA-2011:0975-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0975.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4341" ref_url="http://linux.oracle.com/cve/CVE-2010-4341.html" source="CVE"/>
        <description>The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:19.161-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:19.795-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:29.026-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23117 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.316-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:25.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="sssd is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:105059"/>
          <criterion comment="sssd-client is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:104528"/>
          <criterion comment="sssd-tools is earlier than 0:1.5.1-37.el5" test_ref="oval:org.mitre.oval:tst:105152"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23115" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0676: kvm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2012:0676-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-0676.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1601" ref_url="http://linux.oracle.com/cve/CVE-2012-1601.html" source="CVE"/>
        <reference ref_id="CVE-2012-2121" ref_url="http://linux.oracle.com/cve/CVE-2012-2121.html" source="CVE"/>
        <description>The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (memory leak and host OS crash) by leveraging administrative access to the guest OS to conduct hotunplug and hotplug operations on devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:01.422-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:19.586-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:28.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23115 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:16.410-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:25.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kmod-kvm is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:106192"/>
          <criterion comment="kvm-tools is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:106210"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:106009"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:105596"/>
          <criterion comment="kvm is earlier than 0:83-249.el5_8.4" test_ref="oval:org.mitre.oval:tst:105340"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23114" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0720: mikmod security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>mikmod</product>
        </affected>
        <reference ref_id="ELSA-2010:0720-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0720.html" source="VENDOR"/>
        <reference ref_id="CVE-2007-6720" ref_url="http://linux.oracle.com/cve/CVE-2007-6720.html" source="CVE"/>
        <reference ref_id="CVE-2009-3995" ref_url="http://linux.oracle.com/cve/CVE-2009-3995.html" source="CVE"/>
        <reference ref_id="CVE-2009-3996" ref_url="http://linux.oracle.com/cve/CVE-2009-3996.html" source="CVE"/>
        <description>Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:32.435-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:19.482-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:28.545-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23114 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:16.173-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:25.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mikmod is earlier than 0:3.1.6-39.el5_5.1" test_ref="oval:org.mitre.oval:tst:104366"/>
          <criterion comment="mikmod-devel is earlier than 0:3.1.6-39.el5_5.1" test_ref="oval:org.mitre.oval:tst:104387"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23113" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1868: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2013:1868-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1868.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6424" ref_url="http://linux.oracle.com/cve/CVE-2013-6424.html" source="CVE"/>
        <description>Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:26.962-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:19.388-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:28.391-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23113 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:16.074-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:25.265-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:03:23.099-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:03:23.099-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107467"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107801"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107853"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107907"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107899"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107946"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107904"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:107741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107726"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107906"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107864"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107757"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107990"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107754"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107831"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107891"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:107941"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23112" version="22" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0095: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference ref_id="ELSA-2012:0095-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0095.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3743" ref_url="http://linux.oracle.com/cve/CVE-2009-3743.html" source="CVE"/>
        <reference ref_id="CVE-2010-2055" ref_url="http://linux.oracle.com/cve/CVE-2010-2055.html" source="CVE"/>
        <reference ref_id="CVE-2010-4054" ref_url="http://linux.oracle.com/cve/CVE-2010-4054.html" source="CVE"/>
        <reference ref_id="CVE-2010-4820" ref_url="http://linux.oracle.com/cve/CVE-2010-4820.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:14.936-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:19.134-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:28.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23112 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.944-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:25.046-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:02:02.866-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:02:02.866-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:110103"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:109660"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:109848"/>
            <criterion comment="ghostscript is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:109793"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:110071"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:109972"/>
            <criterion comment="ghostscript is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:109765"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23111" version="30" class="patch">
      <metadata>
        <title>ELSA-2011:0490: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0490-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0490.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:17.397-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:18.881-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:27.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23111 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.497-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:24.875-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104655"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104714"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104948"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104059"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104710"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104917"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.9-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104422"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23110" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0430: postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
        </affected>
        <reference ref_id="ELSA-2010:0430-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0430.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1169" ref_url="http://linux.oracle.com/cve/CVE-2010-1169.html" source="CVE"/>
        <reference ref_id="CVE-2010-1170" ref_url="http://linux.oracle.com/cve/CVE-2010-1170.html" source="CVE"/>
        <reference ref_id="CVE-2010-1975" ref_url="http://linux.oracle.com/cve/CVE-2010-1975.html" source="CVE"/>
        <description>PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:09.842-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:18.758-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:27.522-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23110 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.133-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:24.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql84-tcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103359"/>
          <criterion comment="postgresql84-docs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103721"/>
          <criterion comment="postgresql84-python is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:104026"/>
          <criterion comment="postgresql84-plpython is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103722"/>
          <criterion comment="postgresql84-test is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103957"/>
          <criterion comment="postgresql84-libs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103522"/>
          <criterion comment="postgresql84-server is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103407"/>
          <criterion comment="postgresql84-pltcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103880"/>
          <criterion comment="postgresql84-plperl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103960"/>
          <criterion comment="postgresql84-devel is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103970"/>
          <criterion comment="postgresql84 is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103624"/>
          <criterion comment="postgresql84-contrib is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103080"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23107" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1359: xorg-x11-server security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2011:1359-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1359.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4818" ref_url="http://linux.oracle.com/cve/CVE-2010-4818.html" source="CVE"/>
        <reference ref_id="CVE-2010-4819" ref_url="http://linux.oracle.com/cve/CVE-2010-4819.html" source="CVE"/>
        <description>The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:41.408-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:18.402-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:26.821-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23107 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.526-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:24.049-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T16:01:11.666-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T16:01:11.666-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:105188"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:105254"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:105189"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:105308"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:105047"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:104811"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:105061"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:105239"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:105275"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:105149"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:105202"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:104910"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:105252"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:105206"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:104441"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:104963"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:105145"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23106" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0392: libtiff security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2011:0392-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0392.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1167" ref_url="http://linux.oracle.com/cve/CVE-2011-1167.html" source="CVE"/>
        <description>Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:42.228-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:18.314-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:26.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23106 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.519-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:23.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:108422"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:108194"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:108777"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:108776"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:108602"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23105" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1362: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1362-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1362.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4193" ref_url="http://linux.oracle.com/cve/CVE-2012-4193.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:37.394-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:18.255-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:26.596-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23105 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.655-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:23.867-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:59:47.688-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:59:47.688-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:106371"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:106979"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23104" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:1181: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2012:1181-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1181.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3909" ref_url="http://linux.oracle.com/cve/CVE-2009-3909.html" source="CVE"/>
        <reference ref_id="CVE-2011-2896" ref_url="http://linux.oracle.com/cve/CVE-2011-2896.html" source="CVE"/>
        <reference ref_id="CVE-2012-3402" ref_url="http://linux.oracle.com/cve/CVE-2012-3402.html" source="CVE"/>
        <reference ref_id="CVE-2012-3403" ref_url="http://linux.oracle.com/cve/CVE-2012-3403.html" source="CVE"/>
        <reference ref_id="CVE-2012-3481" ref_url="http://linux.oracle.com/cve/CVE-2012-3481.html" source="CVE"/>
        <description>Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:35.636-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:18.120-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:26.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23104 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.691-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:23.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gimp-libs is earlier than 2:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:106783"/>
          <criterion comment="gimp-devel is earlier than 2:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:106796"/>
          <criterion comment="gimp is earlier than 2:2.2.13-2.0.7.el5_8.5" test_ref="oval:org.mitre.oval:tst:106607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23103" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0486: xmlsec1 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xmlsec1</product>
        </affected>
        <reference ref_id="ELSA-2011:0486-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0486.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1425" ref_url="http://linux.oracle.com/cve/CVE-2011-1425.html" source="CVE"/>
        <description>xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:26.803-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:18.036-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:26.260-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23103 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.013-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:23.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xmlsec1-nss-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:104762"/>
          <criterion comment="xmlsec1-openssl is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:104999"/>
          <criterion comment="xmlsec1-nss is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:104894"/>
          <criterion comment="xmlsec1-gnutls is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:104424"/>
          <criterion comment="xmlsec1 is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:104830"/>
          <criterion comment="xmlsec1-gnutls-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:104858"/>
          <criterion comment="xmlsec1-openssl-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:105011"/>
          <criterion comment="xmlsec1-devel is earlier than 0:1.2.9-8.1.2" test_ref="oval:org.mitre.oval:tst:104036"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23102" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0051: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2012:0051-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0051.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4622" ref_url="http://linux.oracle.com/cve/CVE-2011-4622.html" source="CVE"/>
        <reference ref_id="CVE-2012-0029" ref_url="http://linux.oracle.com/cve/CVE-2012-0029.html" source="CVE"/>
        <description>Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:00.047-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:17.948-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:26.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23102 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.881-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:23.454-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kvm is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:105580"/>
          <criterion comment="kmod-kvm is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:105434"/>
          <criterion comment="kvm-tools is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:105559"/>
          <criterion comment="kmod-kvm-debug is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:105555"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-239.el5_7.1" test_ref="oval:org.mitre.oval:tst:105399"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23101" version="33" class="patch">
      <metadata>
        <title>ELSA-2010:0919: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2010:0919-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0919.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-5016" ref_url="http://linux.oracle.com/cve/CVE-2009-5016.html" source="CVE"/>
        <reference ref_id="CVE-2010-0397" ref_url="http://linux.oracle.com/cve/CVE-2010-0397.html" source="CVE"/>
        <reference ref_id="CVE-2010-1128" ref_url="http://linux.oracle.com/cve/CVE-2010-1128.html" source="CVE"/>
        <reference ref_id="CVE-2010-1917" ref_url="http://linux.oracle.com/cve/CVE-2010-1917.html" source="CVE"/>
        <reference ref_id="CVE-2010-2531" ref_url="http://linux.oracle.com/cve/CVE-2010-2531.html" source="CVE"/>
        <reference ref_id="CVE-2010-3065" ref_url="http://linux.oracle.com/cve/CVE-2010-3065.html" source="CVE"/>
        <reference ref_id="CVE-2010-3870" ref_url="http://linux.oracle.com/cve/CVE-2010-3870.html" source="CVE"/>
        <description>The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:16.658-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:17.721-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:25.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23101 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.325-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:23.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-common is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104591"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:103961"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104324"/>
          <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104058"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104460"/>
          <criterion comment="php is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104484"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104077"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:103627"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104416"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104364"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:103827"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104523"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104480"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104396"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104161"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104319"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104256"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104499"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_5.3" test_ref="oval:org.mitre.oval:tst:104510"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23100" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1043: libwpd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libwpd</product>
        </affected>
        <reference ref_id="ELSA-2012:1043-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1043.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2149" ref_url="http://linux.oracle.com/cve/CVE-2012-2149.html" source="CVE"/>
        <description>The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used.  NOTE: some sources report this issue as an integer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:21:56.915-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:17.611-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:25.661-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23100 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.961-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:22.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libwpd-devel is earlier than 0:0.8.7-3.1.el5_8" test_ref="oval:org.mitre.oval:tst:105652"/>
          <criterion comment="libwpd is earlier than 0:0.8.7-3.1.el5_8" test_ref="oval:org.mitre.oval:tst:106553"/>
          <criterion comment="libwpd-tools is earlier than 0:0.8.7-3.1.el5_8" test_ref="oval:org.mitre.oval:tst:106587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23099" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1361: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1361-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1361.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4193" ref_url="http://linux.oracle.com/cve/CVE-2012-4193.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:39.887-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:17.480-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:25.548-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23099 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.749-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:22.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:106684"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:106440"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:107017"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:106760"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23098" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1268: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2011:1268-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1268.html" source="VENDOR"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
The RHSA-2011:1242 Firefox update rendered HTTPS certificates signed by a
certain Certificate Authority (CA) as untrusted, but made an exception for
a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)
All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.22. After installing the update, Firefox must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:21.569-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:17.382-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:25.454-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23098 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.792-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:22.800-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:105329"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:104883"/>
            <criterion comment="firefox is earlier than 0:3.6.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:104360"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:105278"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:104895"/>
            <criterion comment="firefox is earlier than 0:3.6.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:105356"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23097" version="105" class="patch">
      <metadata>
        <title>ELSA-2010:0338: java-1.5.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.5.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2010:0338-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0338.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-0082" ref_url="http://linux.oracle.com/cve/CVE-2010-0082.html" source="CVE"/>
        <reference ref_id="CVE-2010-0084" ref_url="http://linux.oracle.com/cve/CVE-2010-0084.html" source="CVE"/>
        <reference ref_id="CVE-2010-0085" ref_url="http://linux.oracle.com/cve/CVE-2010-0085.html" source="CVE"/>
        <reference ref_id="CVE-2010-0087" ref_url="http://linux.oracle.com/cve/CVE-2010-0087.html" source="CVE"/>
        <reference ref_id="CVE-2010-0088" ref_url="http://linux.oracle.com/cve/CVE-2010-0088.html" source="CVE"/>
        <reference ref_id="CVE-2010-0089" ref_url="http://linux.oracle.com/cve/CVE-2010-0089.html" source="CVE"/>
        <reference ref_id="CVE-2010-0091" ref_url="http://linux.oracle.com/cve/CVE-2010-0091.html" source="CVE"/>
        <reference ref_id="CVE-2010-0092" ref_url="http://linux.oracle.com/cve/CVE-2010-0092.html" source="CVE"/>
        <reference ref_id="CVE-2010-0093" ref_url="http://linux.oracle.com/cve/CVE-2010-0093.html" source="CVE"/>
        <reference ref_id="CVE-2010-0094" ref_url="http://linux.oracle.com/cve/CVE-2010-0094.html" source="CVE"/>
        <reference ref_id="CVE-2010-0095" ref_url="http://linux.oracle.com/cve/CVE-2010-0095.html" source="CVE"/>
        <reference ref_id="CVE-2010-0837" ref_url="http://linux.oracle.com/cve/CVE-2010-0837.html" source="CVE"/>
        <reference ref_id="CVE-2010-0838" ref_url="http://linux.oracle.com/cve/CVE-2010-0838.html" source="CVE"/>
        <reference ref_id="CVE-2010-0839" ref_url="http://linux.oracle.com/cve/CVE-2010-0839.html" source="CVE"/>
        <reference ref_id="CVE-2010-0840" ref_url="http://linux.oracle.com/cve/CVE-2010-0840.html" source="CVE"/>
        <reference ref_id="CVE-2010-0841" ref_url="http://linux.oracle.com/cve/CVE-2010-0841.html" source="CVE"/>
        <reference ref_id="CVE-2010-0842" ref_url="http://linux.oracle.com/cve/CVE-2010-0842.html" source="CVE"/>
        <reference ref_id="CVE-2010-0843" ref_url="http://linux.oracle.com/cve/CVE-2010-0843.html" source="CVE"/>
        <reference ref_id="CVE-2010-0844" ref_url="http://linux.oracle.com/cve/CVE-2010-0844.html" source="CVE"/>
        <reference ref_id="CVE-2010-0845" ref_url="http://linux.oracle.com/cve/CVE-2010-0845.html" source="CVE"/>
        <reference ref_id="CVE-2010-0846" ref_url="http://linux.oracle.com/cve/CVE-2010-0846.html" source="CVE"/>
        <reference ref_id="CVE-2010-0847" ref_url="http://linux.oracle.com/cve/CVE-2010-0847.html" source="CVE"/>
        <reference ref_id="CVE-2010-0848" ref_url="http://linux.oracle.com/cve/CVE-2010-0848.html" source="CVE"/>
        <reference ref_id="CVE-2010-0849" ref_url="http://linux.oracle.com/cve/CVE-2010-0849.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.	NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:44.641-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:16.906-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:24.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23097 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.747-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:22.662-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-sun-uninstall is earlier than 0:1.5.0.22-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103711"/>
          <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.22-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103948"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23096" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:0429: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0429-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0429.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4346" ref_url="http://linux.oracle.com/cve/CVE-2010-4346.html" source="CVE"/>
        <reference ref_id="CVE-2011-0521" ref_url="http://linux.oracle.com/cve/CVE-2011-0521.html" source="CVE"/>
        <reference ref_id="CVE-2011-0710" ref_url="http://linux.oracle.com/cve/CVE-2011-0710.html" source="CVE"/>
        <reference ref_id="CVE-2011-1010" ref_url="http://linux.oracle.com/cve/CVE-2011-1010.html" source="CVE"/>
        <reference ref_id="CVE-2011-1090" ref_url="http://linux.oracle.com/cve/CVE-2011-1090.html" source="CVE"/>
        <reference ref_id="CVE-2011-1478" ref_url="http://linux.oracle.com/cve/CVE-2011-1478.html" source="CVE"/>
        <description>The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:18.165-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:16.744-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:24.185-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23096 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.816-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:22.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104244"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104732"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:105000"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:103999"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104686"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104574"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104916"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104475"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104952"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104904"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104570"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.9.1.el5" test_ref="oval:org.mitre.oval:tst:104595"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23093" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0387: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0387-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0387.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0451" ref_url="http://linux.oracle.com/cve/CVE-2012-0451.html" source="CVE"/>
        <reference ref_id="CVE-2012-0455" ref_url="http://linux.oracle.com/cve/CVE-2012-0455.html" source="CVE"/>
        <reference ref_id="CVE-2012-0456" ref_url="http://linux.oracle.com/cve/CVE-2012-0456.html" source="CVE"/>
        <reference ref_id="CVE-2012-0457" ref_url="http://linux.oracle.com/cve/CVE-2012-0457.html" source="CVE"/>
        <reference ref_id="CVE-2012-0458" ref_url="http://linux.oracle.com/cve/CVE-2012-0458.html" source="CVE"/>
        <reference ref_id="CVE-2012-0459" ref_url="http://linux.oracle.com/cve/CVE-2012-0459.html" source="CVE"/>
        <reference ref_id="CVE-2012-0460" ref_url="http://linux.oracle.com/cve/CVE-2012-0460.html" source="CVE"/>
        <reference ref_id="CVE-2012-0461" ref_url="http://linux.oracle.com/cve/CVE-2012-0461.html" source="CVE"/>
        <reference ref_id="CVE-2012-0462" ref_url="http://linux.oracle.com/cve/CVE-2012-0462.html" source="CVE"/>
        <reference ref_id="CVE-2012-0464" ref_url="http://linux.oracle.com/cve/CVE-2012-0464.html" source="CVE"/>
        <description>Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:03.225-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:16.349-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:23.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23093 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.510-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:22.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:110126"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:109901"/>
            <criterion comment="firefox is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:110074"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:109824"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:109761"/>
            <criterion comment="firefox is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:110065"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23092" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1160: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dhcp</product>
        </affected>
        <reference ref_id="ELSA-2011:1160-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1160.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2748" ref_url="http://linux.oracle.com/cve/CVE-2011-2748.html" source="CVE"/>
        <reference ref_id="CVE-2011-2749" ref_url="http://linux.oracle.com/cve/CVE-2011-2749.html" source="CVE"/>
        <description>The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:17.144-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:16.238-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:23.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23092 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:20.277-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:22.001-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:59:16.565-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:59:16.565-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libdhcp4client is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:109178"/>
            <criterion comment="dhclient is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:109248"/>
            <criterion comment="dhcp-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:108615"/>
            <criterion comment="dhcp is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:109077"/>
            <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:108996"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dhclient is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:108591"/>
            <criterion comment="dhcp-devel is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109150"/>
            <criterion comment="dhcp is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109044"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23091" version="37" class="patch">
      <metadata>
        <title>ELSA-2012:0007: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0007-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0007.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1020" ref_url="http://linux.oracle.com/cve/CVE-2011-1020.html" source="CVE"/>
        <reference ref_id="CVE-2011-3637" ref_url="http://linux.oracle.com/cve/CVE-2011-3637.html" source="CVE"/>
        <reference ref_id="CVE-2011-4077" ref_url="http://linux.oracle.com/cve/CVE-2011-4077.html" source="CVE"/>
        <reference ref_id="CVE-2011-4132" ref_url="http://linux.oracle.com/cve/CVE-2011-4132.html" source="CVE"/>
        <reference ref_id="CVE-2011-4324" ref_url="http://linux.oracle.com/cve/CVE-2011-4324.html" source="CVE"/>
        <reference ref_id="CVE-2011-4325" ref_url="http://linux.oracle.com/cve/CVE-2011-4325.html" source="CVE"/>
        <reference ref_id="CVE-2011-4330" ref_url="http://linux.oracle.com/cve/CVE-2011-4330.html" source="CVE"/>
        <reference ref_id="CVE-2011-4348" ref_url="http://linux.oracle.com/cve/CVE-2011-4348.html" source="CVE"/>
        <description>Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets.	 NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:04.471-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:16.035-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.983-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23091 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.274-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:21.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105160"/>
          <criterion comment="kernel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105461"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105630"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105577"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105680"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105327"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105594"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105279"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105499"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105497"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105225"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-274.17.1.el5" test_ref="oval:org.mitre.oval:tst:105273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23090" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0164: openssl097a security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl097a</product>
        </affected>
        <reference ref_id="ELSA-2010:0164-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0164.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:54.912-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.969-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.880-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23090 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.864-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:21.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="openssl097a is earlier than 0:0.9.7a-9.el5_4.2" test_ref="oval:org.mitre.oval:tst:103676"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23089" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1213: gdm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gdm</product>
          <product>initscripts</product>
        </affected>
        <reference ref_id="ELSA-2013:1213-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1213.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4169" ref_url="http://linux.oracle.com/cve/CVE-2013-4169.html" source="CVE"/>
        <description>GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:27.208-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.907-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23089 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:20.040-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:21.573-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="initscripts is earlier than 0:8.45.42-2.el5_9.1" test_ref="oval:org.mitre.oval:tst:107388"/>
          <criterion comment="gdm is earlier than 1:2.16.0-59.el5_9.1" test_ref="oval:org.mitre.oval:tst:107711"/>
          <criterion comment="gdm-docs is earlier than 1:2.16.0-59.el5_9.1" test_ref="oval:org.mitre.oval:tst:107139"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23088" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0346: openldap security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference ref_id="ELSA-2011:0346-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0346.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1024" ref_url="http://linux.oracle.com/cve/CVE-2011-1024.html" source="CVE"/>
        <description>chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:02.727-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.840-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.666-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23088 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:16.502-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:21.442-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:104503"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:104495"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:104353"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:104758"/>
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:104611"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:104410"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5_6.7" test_ref="oval:org.mitre.oval:tst:104544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23087" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0324: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:0324-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0324.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0841" ref_url="http://linux.oracle.com/cve/CVE-2012-0841.html" source="CVE"/>
        <description>libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:47.862-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.736-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.549-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23087 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.151-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:21.336-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:58:20.031-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:58:20.031-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:105350"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:105682"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:105753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:105400"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:105835"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:105530"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:105062"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23086" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0196: php53 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php53</product>
        </affected>
        <reference ref_id="ELSA-2011:0196-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0196.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3710" ref_url="http://linux.oracle.com/cve/CVE-2010-3710.html" source="CVE"/>
        <reference ref_id="CVE-2010-4156" ref_url="http://linux.oracle.com/cve/CVE-2010-4156.html" source="CVE"/>
        <reference ref_id="CVE-2010-4645" ref_url="http://linux.oracle.com/cve/CVE-2010-4645.html" source="CVE"/>
        <description>strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:13.785-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.615-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.346-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23086 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:20.151-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:21.177-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104057"/>
          <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104198"/>
          <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104277"/>
          <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104644"/>
          <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104306"/>
          <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104800"/>
          <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104646"/>
          <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104785"/>
          <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104308"/>
          <criterion comment="php53 is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104692"/>
          <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104432"/>
          <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104843"/>
          <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104670"/>
          <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104098"/>
          <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104199"/>
          <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104464"/>
          <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104840"/>
          <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104653"/>
          <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104437"/>
          <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104546"/>
          <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:104765"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23085" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0347: nss_db security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nss_db</product>
        </affected>
        <reference ref_id="ELSA-2010:0347-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0347.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0826" ref_url="http://linux.oracle.com/cve/CVE-2010-0826.html" source="CVE"/>
        <description>The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid application that uses this module.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:49.375-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.550-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.241-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23085 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.330-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:21.065-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="nss_db is earlier than 0:2.2-35.4.el5_5" test_ref="oval:org.mitre.oval:tst:103889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23084" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0170: libuser security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libuser</product>
        </affected>
        <reference ref_id="ELSA-2011:0170-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0170.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0002" ref_url="http://linux.oracle.com/cve/CVE-2011-0002.html" source="CVE"/>
        <description>libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:21.104-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.478-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:22.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23084 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.152-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:20.959-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:57:30.546-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:57:30.546-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libuser-devel is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:104618"/>
            <criterion comment="libuser is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:104462"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libuser-devel is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:104381"/>
            <criterion comment="libuser is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:104130"/>
            <criterion comment="libuser-python is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:104338"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23083" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0627: kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2010:0627-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0627.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0431" ref_url="http://linux.oracle.com/cve/CVE-2010-0431.html" source="CVE"/>
        <reference ref_id="CVE-2010-0435" ref_url="http://linux.oracle.com/cve/CVE-2010-0435.html" source="CVE"/>
        <reference ref_id="CVE-2010-2784" ref_url="http://linux.oracle.com/cve/CVE-2010-2784.html" source="CVE"/>
        <description>The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly select the index for access to the callback array, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:58.820-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.376-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:21.954-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23083 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.250-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:20.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kvm-qemu-img is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:104294"/>
          <criterion comment="kvm is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:104039"/>
          <criterion comment="kmod-kvm is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:103987"/>
          <criterion comment="kvm-tools is earlier than 0:83-164.el5_5.21" test_ref="oval:org.mitre.oval:tst:103331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23082" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0361: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2010:0361-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0361.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1163" ref_url="http://linux.oracle.com/cve/CVE-2010-1163.html" source="CVE"/>
        <description>The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:49.179-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.313-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:21.861-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23082 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.415-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:20.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-6.el5_5" test_ref="oval:org.mitre.oval:tst:103071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23081" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0428: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2012:0428-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0428.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4128" ref_url="http://linux.oracle.com/cve/CVE-2011-4128.html" source="CVE"/>
        <reference ref_id="CVE-2012-1569" ref_url="http://linux.oracle.com/cve/CVE-2012-1569.html" source="CVE"/>
        <reference ref_id="CVE-2012-1573" ref_url="http://linux.oracle.com/cve/CVE-2012-1573.html" source="CVE"/>
        <description>gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:55.731-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.215-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:21.684-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23081 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.625-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:20.590-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnutls is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:106053"/>
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:105780"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-7.el5_8.2" test_ref="oval:org.mitre.oval:tst:105848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23080" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0302: cups security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference ref_id="ELSA-2012:0302-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0302.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2896" ref_url="http://linux.oracle.com/cve/CVE-2011-2896.html" source="CVE"/>
        <description>The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:02.153-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.147-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:21.583-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23080 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:16.585-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:20.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="cups-lpd is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:105854"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:105863"/>
          <criterion comment="cups-devel is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:105786"/>
          <criterion comment="cups is earlier than 1:1.3.7-30.el5" test_ref="oval:org.mitre.oval:tst:105922"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23079" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0126: kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2010:0126-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0126.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3722" ref_url="http://linux.oracle.com/cve/CVE-2009-3722.html" source="CVE"/>
        <reference ref_id="CVE-2010-0419" ref_url="http://linux.oracle.com/cve/CVE-2010-0419.html" source="CVE"/>
        <description>The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which might allow guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:51.816-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:15.066-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:21.439-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23079 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.836-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:20.356-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kvm-qemu-img is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:103463"/>
          <criterion comment="kvm is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:103563"/>
          <criterion comment="kmod-kvm is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:103648"/>
          <criterion comment="kvm-tools is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:103606"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23078" version="21" class="patch">
      <metadata>
        <title>ELSA-2010:0580: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference ref_id="ELSA-2010:0580-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0580.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2693" ref_url="http://linux.oracle.com/cve/CVE-2009-2693.html" source="CVE"/>
        <reference ref_id="CVE-2009-2696" ref_url="http://linux.oracle.com/cve/CVE-2009-2696.html" source="CVE"/>
        <reference ref_id="CVE-2009-2902" ref_url="http://linux.oracle.com/cve/CVE-2009-2902.html" source="CVE"/>
        <reference ref_id="CVE-2010-2227" ref_url="http://linux.oracle.com/cve/CVE-2010-2227.html" source="CVE"/>
        <description>Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:53.489-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.943-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:21.184-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23078 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.954-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:20.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104191"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:103837"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:103942"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104014"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104124"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104135"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104170"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104211"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104083"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:103972"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.9.el5_5" test_ref="oval:org.mitre.oval:tst:104235"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23077" version="37" class="patch">
      <metadata>
        <title>ELSA-2012:0006: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:0006-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0006.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3389" ref_url="http://linux.oracle.com/cve/CVE-2011-3389.html" source="CVE"/>
        <reference ref_id="CVE-2011-3545" ref_url="http://linux.oracle.com/cve/CVE-2011-3545.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3549" ref_url="http://linux.oracle.com/cve/CVE-2011-3549.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <reference ref_id="CVE-2011-3557" ref_url="http://linux.oracle.com/cve/CVE-2011-3557.html" source="CVE"/>
        <reference ref_id="CVE-2011-3560" ref_url="http://linux.oracle.com/cve/CVE-2011-3560.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:18:03.248-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.747-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:20.783-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23077 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.936-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:19.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105558"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105291"/>
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105501"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105704"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105683"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105344"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.11-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23076" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1122: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference ref_id="ELSA-2012:1122-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1122.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3817" ref_url="http://linux.oracle.com/cve/CVE-2012-3817.html" source="CVE"/>
        <description>ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:02.729-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.675-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:20.684-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23076 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.056-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:19.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:106016"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:106621"/>
          <criterion comment="bind97-utils is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:106637"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:106710"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-10.P2.el5_8.2" test_ref="oval:org.mitre.oval:tst:106675"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23074" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0496: xen security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference ref_id="ELSA-2011:0496-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0496.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1583" ref_url="http://linux.oracle.com/cve/CVE-2011-1583.html" source="CVE"/>
        <description>Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:17.995-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.551-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:20.500-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23074 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:17.389-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:19.584-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xen is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:104515"/>
          <criterion comment="xen-libs is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:104519"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-120.el5_6.2" test_ref="oval:org.mitre.oval:tst:104470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23073" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0124: systemtap security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2010:0124-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0124.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4273" ref_url="http://linux.oracle.com/cve/CVE-2009-4273.html" source="CVE"/>
        <reference ref_id="CVE-2010-0411" ref_url="http://linux.oracle.com/cve/CVE-2010-0411.html" source="CVE"/>
        <description>Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:52.270-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.461-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:20.356-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23073 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:15.614-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:19.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="systemtap-runtime is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:103418"/>
          <criterion comment="systemtap-testsuite is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:103774"/>
          <criterion comment="systemtap is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:103758"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:103507"/>
          <criterion comment="systemtap-client is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:103449"/>
          <criterion comment="systemtap-initscript is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:103009"/>
          <criterion comment="systemtap-server is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:103749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23072" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1455: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2011:1455-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1455.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3439" ref_url="http://linux.oracle.com/cve/CVE-2011-3439.html" source="CVE"/>
        <description>FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:30.985-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.389-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:20.192-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23072 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:18.062-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:19.322-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:56:49.266-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:56:49.266-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:105454"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:105121"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:105495"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:105318"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:105260"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:105410"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23071" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0291: gfs-kmod security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gfs-kmod</product>
        </affected>
        <reference ref_id="ELSA-2010:0291-04" ref_url="http://linux.oracle.com/errata/ELSA-2010-0291.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0727" ref_url="http://linux.oracle.com/cve/CVE-2010-0727.html" source="CVE"/>
        <description>The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:55.416-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.313-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:20.094-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23071 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:20.372-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:19.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kmod-gfs is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:103316"/>
          <criterion comment="kmod-gfs-PAE is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:103866"/>
          <criterion comment="kmod-gfs-xen is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:103930"/>
          <criterion comment="gfs-kmod is earlier than 0:0.1.34-12.el5" test_ref="oval:org.mitre.oval:tst:103874"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23070" version="29" class="patch">
      <metadata>
        <title>ELSA-2010:0147: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0147-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0147.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4308" ref_url="http://linux.oracle.com/cve/CVE-2009-4308.html" source="CVE"/>
        <reference ref_id="CVE-2010-0003" ref_url="http://linux.oracle.com/cve/CVE-2010-0003.html" source="CVE"/>
        <reference ref_id="CVE-2010-0007" ref_url="http://linux.oracle.com/cve/CVE-2010-0007.html" source="CVE"/>
        <reference ref_id="CVE-2010-0008" ref_url="http://linux.oracle.com/cve/CVE-2010-0008.html" source="CVE"/>
        <reference ref_id="CVE-2010-0415" ref_url="http://linux.oracle.com/cve/CVE-2010-0415.html" source="CVE"/>
        <reference ref_id="CVE-2010-0437" ref_url="http://linux.oracle.com/cve/CVE-2010-0437.html" source="CVE"/>
        <description>The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:50.116-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:14.144-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:19.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23070 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:19.147-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:18.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103720"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103752"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103621"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:102813"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103472"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103462"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103778"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103145"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103732"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:102956"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103329"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:103810"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23069" version="37" class="patch">
      <metadata>
        <title>ELSA-2011:0182: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openoffice.org</product>
        </affected>
        <reference ref_id="ELSA-2011:0182-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0182.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3450" ref_url="http://linux.oracle.com/cve/CVE-2010-3450.html" source="CVE"/>
        <reference ref_id="CVE-2010-3451" ref_url="http://linux.oracle.com/cve/CVE-2010-3451.html" source="CVE"/>
        <reference ref_id="CVE-2010-3452" ref_url="http://linux.oracle.com/cve/CVE-2010-3452.html" source="CVE"/>
        <reference ref_id="CVE-2010-3453" ref_url="http://linux.oracle.com/cve/CVE-2010-3453.html" source="CVE"/>
        <reference ref_id="CVE-2010-3454" ref_url="http://linux.oracle.com/cve/CVE-2010-3454.html" source="CVE"/>
        <reference ref_id="CVE-2010-3689" ref_url="http://linux.oracle.com/cve/CVE-2010-3689.html" source="CVE"/>
        <reference ref_id="CVE-2010-4253" ref_url="http://linux.oracle.com/cve/CVE-2010-4253.html" source="CVE"/>
        <reference ref_id="CVE-2010-4643" ref_url="http://linux.oracle.com/cve/CVE-2010-4643.html" source="CVE"/>
        <description>Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:06.654-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:13.828-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:19.260-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23069 - optimisation of Oracle Linux content" date="2014-05-05T17:51:00.117-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:53:16.821-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:18.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openoffice.org is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104405"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104571"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104435"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104747"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104563"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104514"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104363"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104609"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104598"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104694"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104738"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104768"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104685"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104780"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104576"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104648"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104247"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:103871"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104337"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104687"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104781"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104744"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:103842"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104675"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104582"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104671"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104532"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104764"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104679"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104753"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104079"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104555"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104718"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104540"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104751"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104658"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104789"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104352"/>
          <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104421"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104458"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104356"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104377"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104604"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104496"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104696"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104661"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104456"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104691"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104602"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104695"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104804"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104832"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104394"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104787"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104842"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104440"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104099"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104779"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104599"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104361"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104188"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104291"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104801"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104677"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104466"/>
          <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104486"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104485"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104760"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104089"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104699"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104748"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104689"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104822"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104558"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104701"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104301"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104489"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.5.el5_5.6" test_ref="oval:org.mitre.oval:tst:104681"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23068" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:1540: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1540-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1540.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2372" ref_url="http://linux.oracle.com/cve/CVE-2012-2372.html" source="CVE"/>
        <reference ref_id="CVE-2012-3552" ref_url="http://linux.oracle.com/cve/CVE-2012-3552.html" source="CVE"/>
        <reference ref_id="CVE-2012-4508" ref_url="http://linux.oracle.com/cve/CVE-2012-4508.html" source="CVE"/>
        <reference ref_id="CVE-2012-4535" ref_url="http://linux.oracle.com/cve/CVE-2012-4535.html" source="CVE"/>
        <reference ref_id="CVE-2012-4537" ref_url="http://linux.oracle.com/cve/CVE-2012-4537.html" source="CVE"/>
        <reference ref_id="CVE-2012-5513" ref_url="http://linux.oracle.com/cve/CVE-2012-5513.html" source="CVE"/>
        <description>The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:36.692-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:13.667-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:18.891-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23068 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.415-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:54.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106753"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106781"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106514"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106928"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106965"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106960"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106798"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:107024"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106953"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106956"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106195"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.24.1.el5" test_ref="oval:org.mitre.oval:tst:106801"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23066" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0745: python security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>python</product>
        </affected>
        <reference ref_id="ELSA-2012:0745-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-0745.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4940" ref_url="http://linux.oracle.com/cve/CVE-2011-4940.html" source="CVE"/>
        <reference ref_id="CVE-2011-4944" ref_url="http://linux.oracle.com/cve/CVE-2011-4944.html" source="CVE"/>
        <reference ref_id="CVE-2012-1150" ref_url="http://linux.oracle.com/cve/CVE-2012-1150.html" source="CVE"/>
        <description>Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:08.870-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:13.485-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:18.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23066 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.500-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:18.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="python-devel is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:106608"/>
          <criterion comment="python-libs is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:106200"/>
          <criterion comment="python is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:106357"/>
          <criterion comment="tkinter is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:106410"/>
          <criterion comment="python-tools is earlier than 0:2.4.3-46.el5_8.2" test_ref="oval:org.mitre.oval:tst:105840"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23065" version="61" class="patch">
      <metadata>
        <title>ELSA-2010:0786: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0786-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0786.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3556" ref_url="http://linux.oracle.com/cve/CVE-2010-3556.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <reference ref_id="CVE-2010-3572" ref_url="http://linux.oracle.com/cve/CVE-2010-3572.html" source="CVE"/>
        <description>Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:24.830-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:13.159-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:18.021-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23065 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:03.271-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:18.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104096"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104081"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103555"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104097"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103812"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103755"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.6-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:104229"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23064" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0237: sendmail security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sendmail</product>
        </affected>
        <reference ref_id="ELSA-2010:0237-05" ref_url="http://linux.oracle.com/errata/ELSA-2010-0237.html" source="VENDOR"/>
        <reference ref_id="CVE-2006-7176" ref_url="http://linux.oracle.com/cve/CVE-2006-7176.html" source="CVE"/>
        <reference ref_id="CVE-2009-4565" ref_url="http://linux.oracle.com/cve/CVE-2009-4565.html" source="CVE"/>
        <description>sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:45.603-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:13.076-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:17.889-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23064 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.221-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:18.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="sendmail is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:103731"/>
          <criterion comment="sendmail-doc is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:103918"/>
          <criterion comment="sendmail-devel is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:103858"/>
          <criterion comment="sendmail-cf is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:103542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23063" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0013: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2011:0013-02" ref_url="http://linux.oracle.com/errata/ELSA-2011-0013.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4538" ref_url="http://linux.oracle.com/cve/CVE-2010-4538.html" source="CVE"/>
        <description>Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE) compression.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:20.829-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:13.008-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:17.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23063 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:03.390-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:17.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="wireshark is earlier than 0:1.0.15-1.el5_5.3" test_ref="oval:org.mitre.oval:tst:103768"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_5.3" test_ref="oval:org.mitre.oval:tst:103670"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="wireshark is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:104617"/>
            <criterion comment="wireshark-devel is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:104642"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:104633"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23062" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1219: samba security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2011:1219-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1219.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0547" ref_url="http://linux.oracle.com/cve/CVE-2010-0547.html" source="CVE"/>
        <reference ref_id="CVE-2010-0787" ref_url="http://linux.oracle.com/cve/CVE-2010-0787.html" source="CVE"/>
        <reference ref_id="CVE-2011-1678" ref_url="http://linux.oracle.com/cve/CVE-2011-1678.html" source="CVE"/>
        <reference ref_id="CVE-2011-2522" ref_url="http://linux.oracle.com/cve/CVE-2011-2522.html" source="CVE"/>
        <reference ref_id="CVE-2011-2694" ref_url="http://linux.oracle.com/cve/CVE-2011-2694.html" source="CVE"/>
        <reference ref_id="CVE-2011-3585" ref_url="http://linux.oracle.com/cve/CVE-2011-3585.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:27.594-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.853-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:17.502-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23062 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.559-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:17.750-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:105269"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:104429"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:105191"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:105200"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:104711"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_7.4" test_ref="oval:org.mitre.oval:tst:105084"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23061" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0970: exim security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>exim</product>
        </affected>
        <reference ref_id="ELSA-2010:0970-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0970.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4344" ref_url="http://linux.oracle.com/cve/CVE-2010-4344.html" source="CVE"/>
        <description>Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:21.203-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.793-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:17.399-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23061 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.588-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:17.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="exim-mon is earlier than 0:4.63-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:104302"/>
          <criterion comment="exim is earlier than 0:4.63-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:104616"/>
          <criterion comment="exim-sa is earlier than 0:4.63-5.el5_5.2" test_ref="oval:org.mitre.oval:tst:104509"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23060" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0608: kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2013:0608-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0608.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6075" ref_url="http://linux.oracle.com/cve/CVE-2012-6075.html" source="CVE"/>
        <description>Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:52.865-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.731-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:17.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23060 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.769-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:17.590-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kmod-kvm-debug is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:106992"/>
          <criterion comment="kmod-kvm is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:107164"/>
          <criterion comment="kvm-tools is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:106981"/>
          <criterion comment="kvm is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:107091"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-262.el5_9.1" test_ref="oval:org.mitre.oval:tst:107308"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23058" version="33" class="patch">
      <metadata>
        <title>ELSA-2010:0610: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0610-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0610.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1084" ref_url="http://linux.oracle.com/cve/CVE-2010-1084.html" source="CVE"/>
        <reference ref_id="CVE-2010-2066" ref_url="http://linux.oracle.com/cve/CVE-2010-2066.html" source="CVE"/>
        <reference ref_id="CVE-2010-2070" ref_url="http://linux.oracle.com/cve/CVE-2010-2070.html" source="CVE"/>
        <reference ref_id="CVE-2010-2226" ref_url="http://linux.oracle.com/cve/CVE-2010-2226.html" source="CVE"/>
        <reference ref_id="CVE-2010-2248" ref_url="http://linux.oracle.com/cve/CVE-2010-2248.html" source="CVE"/>
        <reference ref_id="CVE-2010-2521" ref_url="http://linux.oracle.com/cve/CVE-2010-2521.html" source="CVE"/>
        <reference ref_id="CVE-2010-2524" ref_url="http://linux.oracle.com/cve/CVE-2010-2524.html" source="CVE"/>
        <description>The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:04.491-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.474-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:16.863-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23058 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:00.042-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:17.204-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104192"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104134"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104272"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104190"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104093"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:103306"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104193"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104232"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:103257"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:103929"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104220"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.1.el5" test_ref="oval:org.mitre.oval:tst:104184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23057" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0697: samba security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2010:0697-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0697.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3069" ref_url="http://linux.oracle.com/cve/CVE-2010-3069.html" source="CVE"/>
        <description>Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:24.658-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.408-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:16.749-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23057 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.307-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:17.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:104249"/>
          <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:104143"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:104017"/>
          <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:103845"/>
          <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:103719"/>
          <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_5.1" test_ref="oval:org.mitre.oval:tst:103310"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23056" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0122: sudo security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2010:0122-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0122.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0426" ref_url="http://linux.oracle.com/cve/CVE-2010-0426.html" source="CVE"/>
        <reference ref_id="CVE-2010-0427" ref_url="http://linux.oracle.com/cve/CVE-2010-0427.html" source="CVE"/>
        <description>sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:55.927-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.335-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:16.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23056 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:00.306-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:17.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.6.9p17-6.el5_4" test_ref="oval:org.mitre.oval:tst:103475"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23055" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0258: pam_krb5 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pam_krb5</product>
        </affected>
        <reference ref_id="ELSA-2010:0258-04" ref_url="http://linux.oracle.com/errata/ELSA-2010-0258.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-1384" ref_url="http://linux.oracle.com/cve/CVE-2009-1384.html" source="CVE"/>
        <description>pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:04:00.022-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.277-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:16.536-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23055 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.296-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:16.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="pam_krb5 is earlier than 0:2.2.14-15" test_ref="oval:org.mitre.oval:tst:103220"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23054" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0162: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2010:0162-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0162.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3245" ref_url="http://linux.oracle.com/cve/CVE-2009-3245.html" source="CVE"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-0433" ref_url="http://linux.oracle.com/cve/CVE-2010-0433.html" source="CVE"/>
        <description>The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:51.546-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:12.179-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:16.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23054 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.066-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:16.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:103797"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:103798"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:103358"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23053" version="43" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0364: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0364-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0364.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4450" ref_url="http://linux.oracle.com/cve/CVE-2010-4450.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4468" ref_url="http://linux.oracle.com/cve/CVE-2010-4468.html" source="CVE"/>
        <reference ref_id="CVE-2010-4471" ref_url="http://linux.oracle.com/cve/CVE-2010-4471.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:02.965-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.927-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:15.871-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23053 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:00.444-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:16.397-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:56:00.795-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:56:00.795-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104684"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104321"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104580"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104849"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104638"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104927"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104907"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104850"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104575"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104769"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104390"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104778"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104898"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104836"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104553"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23052" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:0412: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2011:0412-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0412.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0296" ref_url="http://linux.oracle.com/cve/CVE-2010-0296.html" source="CVE"/>
        <reference ref_id="CVE-2011-0536" ref_url="http://linux.oracle.com/cve/CVE-2011-0536.html" source="CVE"/>
        <reference ref_id="CVE-2011-1071" ref_url="http://linux.oracle.com/cve/CVE-2011-1071.html" source="CVE"/>
        <reference ref_id="CVE-2011-1095" ref_url="http://linux.oracle.com/cve/CVE-2011-1095.html" source="CVE"/>
        <reference ref_id="CVE-2011-1658" ref_url="http://linux.oracle.com/cve/CVE-2011-1658.html" source="CVE"/>
        <reference ref_id="CVE-2011-1659" ref_url="http://linux.oracle.com/cve/CVE-2011-1659.html" source="CVE"/>
        <description>Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:11.844-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.782-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:15.555-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23052 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.393-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:16.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-common is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:104752"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:104906"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:104868"/>
          <criterion comment="glibc is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:104383"/>
          <criterion comment="nscd is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:104766"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-58.el5_6.2" test_ref="oval:org.mitre.oval:tst:104408"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23051" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0480: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0480-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0480.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1583" ref_url="http://linux.oracle.com/cve/CVE-2012-1583.html" source="CVE"/>
        <description>Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:02.938-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.707-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:15.430-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23051 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.032-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:16.080-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105862"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:106088"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:106099"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105802"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:106094"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105646"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105967"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105814"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105377"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105870"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:106048"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.4.1.el5" test_ref="oval:org.mitre.oval:tst:105983"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23050" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1413: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1413-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1413.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4194" ref_url="http://linux.oracle.com/cve/CVE-2012-4194.html" source="CVE"/>
        <reference ref_id="CVE-2012-4195" ref_url="http://linux.oracle.com/cve/CVE-2012-4195.html" source="CVE"/>
        <reference ref_id="CVE-2012-4196" ref_url="http://linux.oracle.com/cve/CVE-2012-4196.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:44.827-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.612-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:15.243-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23050 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:00.888-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.939-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:54:47.211-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:54:47.211-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:106817"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:106658"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23049" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0382: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2010:0382-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0382.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1166" ref_url="http://linux.oracle.com/cve/CVE-2010-1166.html" source="CVE"/>
        <description>The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:06.457-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.541-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:15.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23049 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:58.457-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103494"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103740"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103265"/>
          <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103557"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103923"/>
          <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103949"/>
          <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103154"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_5.1" test_ref="oval:org.mitre.oval:tst:103649"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23048" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0505: perl-Archive-Tar security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>perl-Archive-Tar</product>
        </affected>
        <reference ref_id="ELSA-2010:0505-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0505.html" source="VENDOR"/>
        <reference ref_id="CVE-2007-4829" ref_url="http://linux.oracle.com/cve/CVE-2007-4829.html" source="CVE"/>
        <description>Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:08.660-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.467-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:15.026-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23048 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.368-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="perl-Archive-Tar is earlier than 1:1.39.1-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:104129"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23047" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0198: openldap security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openldap</product>
        </affected>
        <reference ref_id="ELSA-2010:0198-04" ref_url="http://linux.oracle.com/errata/ELSA-2010-0198.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3767" ref_url="http://linux.oracle.com/cve/CVE-2009-3767.html" source="CVE"/>
        <description>libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:59.651-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.399-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:14.900-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23047 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:58.550-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openldap-devel is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:103745"/>
          <criterion comment="openldap-clients is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:103272"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:103829"/>
          <criterion comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5" test_ref="oval:org.mitre.oval:tst:103419"/>
          <criterion comment="openldap is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:103247"/>
          <criterion comment="openldap-servers is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:102964"/>
          <criterion comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5" test_ref="oval:org.mitre.oval:tst:103222"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23046" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1267: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1267-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1267.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
The RHSA-2011:1243 Thunderbird update rendered HTTPS certificates signed by
a certain Certificate Authority (CA) as untrusted, but made an exception
for a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)
All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:23.569-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.349-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:14.829-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23046 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.445-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.582-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:54:14.257-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:54:14.257-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-25.el5" test_ref="oval:org.mitre.oval:tst:104976"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.14-1.el6_1" test_ref="oval:org.mitre.oval:tst:105280"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23045" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1073: bash security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference ref_id="ELSA-2011:1073-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1073.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-5374" ref_url="http://linux.oracle.com/cve/CVE-2008-5374.html" source="CVE"/>
        <description>bash-doc 3.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/cb#####.? temporary file, related to the (1) aliasconv.sh, (2) aliasconv.bash, and (3) cshtobash scripts.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:25.156-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.286-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:14.731-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23045 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.695-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.474-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="bash is earlier than 0:3.2-32.el5" test_ref="oval:org.mitre.oval:tst:104333"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23044" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1036: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1036-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1036.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2143" ref_url="http://linux.oracle.com/cve/CVE-2012-2143.html" source="CVE"/>
        <description>The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:10.496-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.212-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:14.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23044 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:03.152-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql-test is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106589"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106355"/>
          <criterion comment="postgresql is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106575"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106068"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106469"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106122"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106592"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:105634"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106183"/>
          <criterion comment="postgresql-docs is earlier than 0:8.1.23-5.el5_8" test_ref="oval:org.mitre.oval:tst:106634"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23043" version="22" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0275: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0275-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0275.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-1484" ref_url="http://linux.oracle.com/cve/CVE-2013-1484.html" source="CVE"/>
        <reference ref_id="CVE-2013-1485" ref_url="http://linux.oracle.com/cve/CVE-2013-1485.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:57.571-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:11.070-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:14.337-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23043 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.793-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:15.089-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:53:43.941-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:53:43.941-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:106771"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:107049"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:107115"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:106597"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:106871"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:107166"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:106940"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:107129"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:107210"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:107015"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23042" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0130: httpd security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:0130-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0130.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-0455" ref_url="http://linux.oracle.com/cve/CVE-2008-0455.html" source="CVE"/>
        <reference ref_id="CVE-2008-0456" ref_url="http://linux.oracle.com/cve/CVE-2008-0456.html" source="CVE"/>
        <reference ref_id="CVE-2012-2687" ref_url="http://linux.oracle.com/cve/CVE-2012-2687.html" source="CVE"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:05.988-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.964-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:14.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23042 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.966-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:14.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:106910"/>
          <criterion comment="httpd is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:107025"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:106117"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-74.el5" test_ref="oval:org.mitre.oval:tst:107098"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23041" version="57" class="patch">
      <metadata>
        <title>ELSA-2010:0545: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2010:0545-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0545.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0174" ref_url="http://linux.oracle.com/cve/CVE-2010-0174.html" source="CVE"/>
        <reference ref_id="CVE-2010-0175" ref_url="http://linux.oracle.com/cve/CVE-2010-0175.html" source="CVE"/>
        <reference ref_id="CVE-2010-0176" ref_url="http://linux.oracle.com/cve/CVE-2010-0176.html" source="CVE"/>
        <reference ref_id="CVE-2010-0177" ref_url="http://linux.oracle.com/cve/CVE-2010-0177.html" source="CVE"/>
        <reference ref_id="CVE-2010-1197" ref_url="http://linux.oracle.com/cve/CVE-2010-1197.html" source="CVE"/>
        <reference ref_id="CVE-2010-1198" ref_url="http://linux.oracle.com/cve/CVE-2010-1198.html" source="CVE"/>
        <reference ref_id="CVE-2010-1199" ref_url="http://linux.oracle.com/cve/CVE-2010-1199.html" source="CVE"/>
        <reference ref_id="CVE-2010-1200" ref_url="http://linux.oracle.com/cve/CVE-2010-1200.html" source="CVE"/>
        <reference ref_id="CVE-2010-1205" ref_url="http://linux.oracle.com/cve/CVE-2010-1205.html" source="CVE"/>
        <reference ref_id="CVE-2010-1211" ref_url="http://linux.oracle.com/cve/CVE-2010-1211.html" source="CVE"/>
        <reference ref_id="CVE-2010-1214" ref_url="http://linux.oracle.com/cve/CVE-2010-1214.html" source="CVE"/>
        <reference ref_id="CVE-2010-2753" ref_url="http://linux.oracle.com/cve/CVE-2010-2753.html" source="CVE"/>
        <reference ref_id="CVE-2010-2754" ref_url="http://linux.oracle.com/cve/CVE-2010-2754.html" source="CVE"/>
        <description>dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about script parameters via a crafted HTML document, related to the window.onerror handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:02.372-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.708-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:13.758-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23041 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.428-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:14.702-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-6.el5" test_ref="oval:org.mitre.oval:tst:103237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23039" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1426: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2013:1426-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1426.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4396" ref_url="http://linux.oracle.com/cve/CVE-2013-4396.html" source="CVE"/>
        <description>Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:29.311-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.507-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:13.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23039 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:00.187-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:14.426-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:52:49.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:52:49.289-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107606"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107687"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107556"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:106828"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107241"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107495"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107713"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107525"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:107361"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107772"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107705"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107812"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107416"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107738"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107512"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107470"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:107615"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23038" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0518: scsi-target-utils security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference ref_id="ELSA-2010:0518-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0518.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2221" ref_url="http://linux.oracle.com/cve/CVE-2010-2221.html" source="CVE"/>
        <description>Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:57.508-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.449-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:13.294-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23038 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.111-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:14.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="scsi-target-utils is earlier than 0:0.0-6.20091205snap.el5_5.3" test_ref="oval:org.mitre.oval:tst:104151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23037" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010:0950: apr-util security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr-util</product>
        </affected>
        <reference ref_id="ELSA-2010:0950-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0950.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1623" ref_url="http://linux.oracle.com/cve/CVE-2010-1623.html" source="CVE"/>
        <description>Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:31.262-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.367-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:13.128-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23037 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:03.500-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:14.234-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:51:32.745-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:51:32.745-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:104067"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:104117"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:104481"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:103996"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104398"/>
            <criterion comment="apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104241"/>
            <criterion comment="apr-util-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104585"/>
            <criterion comment="apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104288"/>
            <criterion comment="apr-util is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104474"/>
            <criterion comment="apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104530"/>
            <criterion comment="apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:104487"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23036" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0039: gcc and gcc4 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gcc</product>
          <product>gcc4</product>
        </affected>
        <reference ref_id="ELSA-2010:0039-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0039.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3736" ref_url="http://linux.oracle.com/cve/CVE-2009-3736.html" source="CVE"/>
        <description>ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:56.342-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.274-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:12.989-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23036 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:03.018-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:14.124-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gcc-objc++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103551"/>
          <criterion comment="libgfortran is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103458"/>
          <criterion comment="libgcj-src is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103486"/>
          <criterion comment="libmudflap is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103312"/>
          <criterion comment="gcc-gfortran is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103536"/>
          <criterion comment="libgcj-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103535"/>
          <criterion comment="libgcc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103559"/>
          <criterion comment="cpp is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103281"/>
          <criterion comment="gcc-gnat is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103049"/>
          <criterion comment="libstdc++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103426"/>
          <criterion comment="libmudflap-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:102886"/>
          <criterion comment="gcc-objc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103573"/>
          <criterion comment="gcc-c++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103605"/>
          <criterion comment="gcc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103235"/>
          <criterion comment="gcc-java is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103593"/>
          <criterion comment="libgnat is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103121"/>
          <criterion comment="libgcj is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103273"/>
          <criterion comment="libstdc++-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103352"/>
          <criterion comment="libobjc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:103493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23034" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0423: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2010:0423-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0423.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1321" ref_url="http://linux.oracle.com/cve/CVE-2010-1321.html" source="CVE"/>
        <description>The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:04.009-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.122-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:12.718-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23034 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:00.568-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:103728"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:103902"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:103673"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:103754"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:103900"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23033" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1648: ntp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ntp</product>
        </affected>
        <reference ref_id="ELSA-2009:1648-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1648.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3563" ref_url="http://linux.oracle.com/cve/CVE-2009-3563.html" source="CVE"/>
        <description>ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:27.688-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:10.058-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:12.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23033 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.524-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_4.1" test_ref="oval:org.mitre.oval:tst:103326"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23032" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1444: nss security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2011:1444-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1444.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.
It was found that the Malaysia-based Digicert Sdn. Bhd. subordinate
Certificate Authority (CA) issued HTTPS certificates with weak keys. This
update renders any HTTPS certificates signed by that CA as untrusted. This
covers all uses of the certificates, including SSL, S/MIME, and code
signing. Note: Digicert Sdn. Bhd. is not the same company as found at
digicert.com. (BZ#751366)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
This update also fixes the following bug on Oracle Linux 5.x:
* When using mod_nss with the Apache HTTP Server, a bug in NSS on Red Hat
Enterprise Linux 5 resulted in file descriptors leaking each time the
Apache HTTP Server was restarted with the "service httpd reload" command.
This could have prevented the Apache HTTP Server from functioning properly
if all available file descriptors were consumed. (BZ#743508)
For Red Hat Enterprise Linux 6, these updated packages upgrade NSS to
version 3.12.10. As well, they upgrade NSPR (Netscape Portable Runtime) to
version 4.8.8 and nss-util to version 3.12.10 on Red Hat
Enterprise Linux 6, as required by the NSS update. (BZ#735972, BZ#736272,
BZ#735973)
All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect. In addition, on Red Hat
Enterprise Linux 6, applications using NSPR and nss-util must also be
restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:22.046-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.987-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:12.526-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23032 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.675-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.740-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:50:31.616-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:50:31.616-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:105494"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:105170"/>
            <criterion comment="nss is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:105156"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:105027"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:105547"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:105538"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:105146"/>
            <criterion comment="nss is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:105541"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:104991"/>
            <criterion comment="nspr is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:105334"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:105402"/>
            <criterion comment="nss-util is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:105436"/>
            <criterion comment="nss-util-devel is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:104817"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23031" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:0474: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0474-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0474.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0073" ref_url="http://linux.oracle.com/cve/CVE-2011-0073.html" source="CVE"/>
        <reference ref_id="CVE-2011-0074" ref_url="http://linux.oracle.com/cve/CVE-2011-0074.html" source="CVE"/>
        <reference ref_id="CVE-2011-0075" ref_url="http://linux.oracle.com/cve/CVE-2011-0075.html" source="CVE"/>
        <reference ref_id="CVE-2011-0077" ref_url="http://linux.oracle.com/cve/CVE-2011-0077.html" source="CVE"/>
        <reference ref_id="CVE-2011-0078" ref_url="http://linux.oracle.com/cve/CVE-2011-0078.html" source="CVE"/>
        <reference ref_id="CVE-2011-0080" ref_url="http://linux.oracle.com/cve/CVE-2011-0080.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:19.876-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.816-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:12.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23031 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.866-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="thunderbird is earlier than 0:2.0.0.24-17.el5_6" test_ref="oval:org.mitre.oval:tst:104897"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23030" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0792: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0792-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0792.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3904" ref_url="http://linux.oracle.com/cve/CVE-2010-3904.html" source="CVE"/>
        <description>The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:17.676-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.730-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:12.115-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23030 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:58.919-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104355"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104207"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:103864"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104115"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:103725"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104271"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104275"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104423"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:103767"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104340"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104442"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.17.4.el5" test_ref="oval:org.mitre.oval:tst:104280"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23029" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0257: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference ref_id="ELSA-2011:0257-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0257.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4539" ref_url="http://linux.oracle.com/cve/CVE-2010-4539.html" source="CVE"/>
        <reference ref_id="CVE-2010-4644" ref_url="http://linux.oracle.com/cve/CVE-2010-4644.html" source="CVE"/>
        <description>Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:20.091-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.599-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:11.963-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23029 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.131-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.276-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:104844"/>
          <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:103934"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:104915"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:103943"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:104851"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.1" test_ref="oval:org.mitre.oval:tst:104882"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23028" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0372: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0372-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0372.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0609" ref_url="http://linux.oracle.com/cve/CVE-2011-0609.html" source="CVE"/>
        <description>Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:07.939-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.531-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:11.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23028 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.775-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.173-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:49:25.980-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:49:25.980-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el5" test_ref="oval:org.mitre.oval:tst:104899"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el6" test_ref="oval:org.mitre.oval:tst:104942"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23027" version="7" class="patch">
      <metadata>
        <title>ELSA-2013:0128: conga security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>conga</product>
        </affected>
        <reference ref_id="ELSA-2013:0128-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0128.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3359" ref_url="http://linux.oracle.com/cve/CVE-2012-3359.html" source="CVE"/>
        <description>Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie.  NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:58.692-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.437-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:11.778-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23027 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:59.602-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:13.052-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ricci is earlier than 0:0.12.2-64.el5" test_ref="oval:org.mitre.oval:tst:106703"/>
          <criterion comment="luci is earlier than 0:0.12.2-64.el5" test_ref="oval:org.mitre.oval:tst:106887"/>
          <criterion comment="conga is earlier than 0:0.12.2-64.el5" test_ref="oval:org.mitre.oval:tst:107072"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23026" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1615: xerces-j2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xerces-j2</product>
        </affected>
        <reference ref_id="ELSA-2009:1615-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1615.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2625" ref_url="http://linux.oracle.com/cve/CVE-2009-2625.html" source="CVE"/>
        <description>XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:33.170-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.367-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:11.701-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23026 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.676-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:12.932-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xerces-j2-demo is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:103575"/>
          <criterion comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:103269"/>
          <criterion comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:103581"/>
          <criterion comment="xerces-j2-scripts is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:103027"/>
          <criterion comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:103253"/>
          <criterion comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:103380"/>
          <criterion comment="xerces-j2 is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:103538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23025" version="29" class="patch">
      <metadata>
        <title>ELSA-2010:0040: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2010:0040-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0040.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2687" ref_url="http://linux.oracle.com/cve/CVE-2009-2687.html" source="CVE"/>
        <reference ref_id="CVE-2009-3291" ref_url="http://linux.oracle.com/cve/CVE-2009-3291.html" source="CVE"/>
        <reference ref_id="CVE-2009-3292" ref_url="http://linux.oracle.com/cve/CVE-2009-3292.html" source="CVE"/>
        <reference ref_id="CVE-2009-3546" ref_url="http://linux.oracle.com/cve/CVE-2009-3546.html" source="CVE"/>
        <reference ref_id="CVE-2009-4017" ref_url="http://linux.oracle.com/cve/CVE-2009-4017.html" source="CVE"/>
        <reference ref_id="CVE-2009-4142" ref_url="http://linux.oracle.com/cve/CVE-2009-4142.html" source="CVE"/>
        <description>The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:46.418-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.189-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:11.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23025 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:58.675-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:12.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-gd is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103479"/>
          <criterion comment="php-soap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103653"/>
          <criterion comment="php-common is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103348"/>
          <criterion comment="php-odbc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103588"/>
          <criterion comment="php-mysql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103476"/>
          <criterion comment="php is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:102952"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103632"/>
          <criterion comment="php-cli is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103532"/>
          <criterion comment="php-mbstring is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103242"/>
          <criterion comment="php-pgsql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103488"/>
          <criterion comment="php-xml is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103642"/>
          <criterion comment="php-dba is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103068"/>
          <criterion comment="php-devel is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103127"/>
          <criterion comment="php-bcmath is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103241"/>
          <criterion comment="php-imap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103199"/>
          <criterion comment="php-ncurses is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103635"/>
          <criterion comment="php-snmp is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103368"/>
          <criterion comment="php-pdo is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103598"/>
          <criterion comment="php-ldap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:103063"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23024" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0690: bind97 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>bind97</product>
        </affected>
        <reference ref_id="ELSA-2013:0690-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0690.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2266" ref_url="http://linux.oracle.com/cve/CVE-2013-2266.html" source="CVE"/>
        <description>libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:42.197-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:09.122-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:11.259-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23024 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:58.283-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:12.601-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind97-utils is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:107440"/>
          <criterion comment="bind97 is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:107353"/>
          <criterion comment="bind97-libs is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:107387"/>
          <criterion comment="bind97-chroot is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:107227"/>
          <criterion comment="bind97-devel is earlier than 32:9.7.0-17.P2.el5_9.1" test_ref="oval:org.mitre.oval:tst:107064"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23023" version="69" class="patch">
      <metadata>
        <title>ELSA-2010:0547: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2010:0547-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0547.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0654" ref_url="http://linux.oracle.com/cve/CVE-2010-0654.html" source="CVE"/>
        <reference ref_id="CVE-2010-1205" ref_url="http://linux.oracle.com/cve/CVE-2010-1205.html" source="CVE"/>
        <reference ref_id="CVE-2010-1206" ref_url="http://linux.oracle.com/cve/CVE-2010-1206.html" source="CVE"/>
        <reference ref_id="CVE-2010-1207" ref_url="http://linux.oracle.com/cve/CVE-2010-1207.html" source="CVE"/>
        <reference ref_id="CVE-2010-1208" ref_url="http://linux.oracle.com/cve/CVE-2010-1208.html" source="CVE"/>
        <reference ref_id="CVE-2010-1209" ref_url="http://linux.oracle.com/cve/CVE-2010-1209.html" source="CVE"/>
        <reference ref_id="CVE-2010-1210" ref_url="http://linux.oracle.com/cve/CVE-2010-1210.html" source="CVE"/>
        <reference ref_id="CVE-2010-1211" ref_url="http://linux.oracle.com/cve/CVE-2010-1211.html" source="CVE"/>
        <reference ref_id="CVE-2010-1212" ref_url="http://linux.oracle.com/cve/CVE-2010-1212.html" source="CVE"/>
        <reference ref_id="CVE-2010-1213" ref_url="http://linux.oracle.com/cve/CVE-2010-1213.html" source="CVE"/>
        <reference ref_id="CVE-2010-1214" ref_url="http://linux.oracle.com/cve/CVE-2010-1214.html" source="CVE"/>
        <reference ref_id="CVE-2010-1215" ref_url="http://linux.oracle.com/cve/CVE-2010-1215.html" source="CVE"/>
        <reference ref_id="CVE-2010-2751" ref_url="http://linux.oracle.com/cve/CVE-2010-2751.html" source="CVE"/>
        <reference ref_id="CVE-2010-2752" ref_url="http://linux.oracle.com/cve/CVE-2010-2752.html" source="CVE"/>
        <reference ref_id="CVE-2010-2753" ref_url="http://linux.oracle.com/cve/CVE-2010-2753.html" source="CVE"/>
        <reference ref_id="CVE-2010-2754" ref_url="http://linux.oracle.com/cve/CVE-2010-2754.html" source="CVE"/>
        <description>dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about script parameters via a crafted HTML document, related to the window.onerror handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:54.061-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:08.764-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:10.646-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23023 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.881-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:12.184-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xulrunner is earlier than 0:1.9.2.7-2.el5" test_ref="oval:org.mitre.oval:tst:103898"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.7-2.el5" test_ref="oval:org.mitre.oval:tst:103528"/>
          <criterion comment="firefox is earlier than 0:3.6.7-2.el5" test_ref="oval:org.mitre.oval:tst:103561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23022" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1187: dovecot security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference ref_id="ELSA-2011:1187-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1187.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1929" ref_url="http://linux.oracle.com/cve/CVE-2011-1929.html" source="CVE"/>
        <description>lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:21.381-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:08.676-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:10.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23022 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:54:58.811-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:12.077-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:48:55.313-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:48:55.313-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="dovecot is earlier than 0:1.0.7-7.el5_7.1" test_ref="oval:org.mitre.oval:tst:105276"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:105132"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:105218"/>
            <criterion comment="dovecot is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:105207"/>
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:104806"/>
            <criterion comment="dovecot-devel is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:105153"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23021" version="21" class="patch">
      <metadata>
        <title>ELSA-2009:1670: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2009:1670-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1670.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3612" ref_url="http://linux.oracle.com/cve/CVE-2009-3612.html" source="CVE"/>
        <reference ref_id="CVE-2009-3620" ref_url="http://linux.oracle.com/cve/CVE-2009-3620.html" source="CVE"/>
        <reference ref_id="CVE-2009-3621" ref_url="http://linux.oracle.com/cve/CVE-2009-3621.html" source="CVE"/>
        <reference ref_id="CVE-2009-3726" ref_url="http://linux.oracle.com/cve/CVE-2009-3726.html" source="CVE"/>
        <description>The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:30.372-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:08.517-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:10.295-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23021 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.000-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:11.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103595"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103162"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103650"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103425"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103404"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103423"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103548"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103553"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:102688"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103618"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103307"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:103367"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23020" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0273: curl security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2010:0273-05" ref_url="http://linux.oracle.com/errata/ELSA-2010-0273.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0734" ref_url="http://linux.oracle.com/cve/CVE-2010-0734.html" source="CVE"/>
        <description>content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:52.903-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:08.456-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:10.197-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23020 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:01.189-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:11.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="curl is earlier than 0:7.15.5-9.el5" test_ref="oval:org.mitre.oval:tst:103843"/>
          <criterion comment="curl-devel is earlier than 0:7.15.5-9.el5" test_ref="oval:org.mitre.oval:tst:103524"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23019" version="54" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0515: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0515-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0515.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3062" ref_url="http://linux.oracle.com/cve/CVE-2011-3062.html" source="CVE"/>
        <reference ref_id="CVE-2012-0467" ref_url="http://linux.oracle.com/cve/CVE-2012-0467.html" source="CVE"/>
        <reference ref_id="CVE-2012-0468" ref_url="http://linux.oracle.com/cve/CVE-2012-0468.html" source="CVE"/>
        <reference ref_id="CVE-2012-0469" ref_url="http://linux.oracle.com/cve/CVE-2012-0469.html" source="CVE"/>
        <reference ref_id="CVE-2012-0470" ref_url="http://linux.oracle.com/cve/CVE-2012-0470.html" source="CVE"/>
        <reference ref_id="CVE-2012-0471" ref_url="http://linux.oracle.com/cve/CVE-2012-0471.html" source="CVE"/>
        <reference ref_id="CVE-2012-0472" ref_url="http://linux.oracle.com/cve/CVE-2012-0472.html" source="CVE"/>
        <reference ref_id="CVE-2012-0473" ref_url="http://linux.oracle.com/cve/CVE-2012-0473.html" source="CVE"/>
        <reference ref_id="CVE-2012-0474" ref_url="http://linux.oracle.com/cve/CVE-2012-0474.html" source="CVE"/>
        <reference ref_id="CVE-2012-0477" ref_url="http://linux.oracle.com/cve/CVE-2012-0477.html" source="CVE"/>
        <reference ref_id="CVE-2012-0478" ref_url="http://linux.oracle.com/cve/CVE-2012-0478.html" source="CVE"/>
        <reference ref_id="CVE-2012-0479" ref_url="http://linux.oracle.com/cve/CVE-2012-0479.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:49.453-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:08.187-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:09.659-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23019 - optimisation of Oracle Linux content" date="2014-05-05T17:53:00.685-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:55:02.186-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:11.202-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:48:10.570-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:48:10.570-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:105625"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:105459"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:105715"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:105957"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:105879"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:105602"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23018" version="31" class="patch">
      <metadata>
        <title>ELSA-2010:0625: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 3</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Oracle Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2010:0625-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0625.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1455" ref_url="http://linux.oracle.com/cve/CVE-2010-1455.html" source="CVE"/>
        <reference ref_id="CVE-2010-2283" ref_url="http://linux.oracle.com/cve/CVE-2010-2283.html" source="CVE"/>
        <reference ref_id="CVE-2010-2284" ref_url="http://linux.oracle.com/cve/CVE-2010-2284.html" source="CVE"/>
        <reference ref_id="CVE-2010-2286" ref_url="http://linux.oracle.com/cve/CVE-2010-2286.html" source="CVE"/>
        <reference ref_id="CVE-2010-2287" ref_url="http://linux.oracle.com/cve/CVE-2010-2287.html" source="CVE"/>
        <reference ref_id="CVE-2010-2995" ref_url="http://linux.oracle.com/cve/CVE-2010-2995.html" source="CVE"/>
        <description>The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:57.033-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:08.038-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:09.389-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23018 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:33.033-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:54.274-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23018 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-23T14:36:06.733-04:00">INTERIM</status_change>
            <status_change date="2014-08-11T04:00:16.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="wireshark is earlier than 0:1.0.15-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:104035"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:104108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23017" version="21" class="patch">
      <metadata>
        <title>ELSA-2010:0737: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2010:0737-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0737.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2806" ref_url="http://linux.oracle.com/cve/CVE-2010-2806.html" source="CVE"/>
        <reference ref_id="CVE-2010-2808" ref_url="http://linux.oracle.com/cve/CVE-2010-2808.html" source="CVE"/>
        <reference ref_id="CVE-2010-3054" ref_url="http://linux.oracle.com/cve/CVE-2010-3054.html" source="CVE"/>
        <reference ref_id="CVE-2010-3311" ref_url="http://linux.oracle.com/cve/CVE-2010-3311.html" source="CVE"/>
        <description>Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:27.028-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.926-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:09.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23017 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.002-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:11.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="freetype is earlier than 0:2.2.1-28.el5_5" test_ref="oval:org.mitre.oval:tst:103881"/>
          <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_5" test_ref="oval:org.mitre.oval:tst:104212"/>
          <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_5" test_ref="oval:org.mitre.oval:tst:104148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23016" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0698: samba3x security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>samba3x</product>
        </affected>
        <reference ref_id="ELSA-2010:0698-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0698.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3069" ref_url="http://linux.oracle.com/cve/CVE-2010-3069.html" source="CVE"/>
        <description>Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:14.976-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.845-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:09.096-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23016 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.019-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:10.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tdb-tools is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:103982"/>
          <criterion comment="samba3x-swat is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104274"/>
          <criterion comment="libtdb is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104183"/>
          <criterion comment="libtalloc-devel is earlier than 0:1.2.0-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104205"/>
          <criterion comment="samba3x-client is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104123"/>
          <criterion comment="samba3x-doc is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104173"/>
          <criterion comment="samba3x-winbind is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:103882"/>
          <criterion comment="samba3x is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104126"/>
          <criterion comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104090"/>
          <criterion comment="libtdb-devel is earlier than 0:1.1.2-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:103390"/>
          <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104243"/>
          <criterion comment="samba3x-common is earlier than 0:3.3.8-0.52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104238"/>
          <criterion comment="libtalloc is earlier than 0:1.2.0-52.el5_5.2" test_ref="oval:org.mitre.oval:tst:104169"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23015" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0102: flash-plugin security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2010:0102-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0102.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0186" ref_url="http://linux.oracle.com/cve/CVE-2010-0186.html" source="CVE"/>
        <reference ref_id="CVE-2010-0187" ref_url="http://linux.oracle.com/cve/CVE-2010-0187.html" source="CVE"/>
        <description>Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:51.272-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.775-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:08.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23015 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.490-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:10.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="flash-plugin is earlier than 0:10.0.45.2-1.el5" test_ref="oval:org.mitre.oval:tst:103710"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23013" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1642: acpid security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>acpid</product>
        </affected>
        <reference ref_id="ELSA-2009:1642-02" ref_url="http://linux.oracle.com/errata/ELSA-2009-1642.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4033" ref_url="http://linux.oracle.com/cve/CVE-2009-4033.html" source="CVE"/>
        <description>A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file, cause a denial of service by overwriting this file, or gain privileges by executing this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:22.140-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.616-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:08.678-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23013 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.319-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:10.567-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="acpid is earlier than 0:1.0.4-9.el5_4.1" test_ref="oval:org.mitre.oval:tst:103438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23012" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0787: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2010:0787-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0787.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3847" ref_url="http://linux.oracle.com/cve/CVE-2010-3847.html" source="CVE"/>
        <description>elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:22.774-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.551-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:08.571-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23012 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.004-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:10.450-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-headers is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:104268"/>
          <criterion comment="glibc-common is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:104433"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:104216"/>
          <criterion comment="glibc is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:104315"/>
          <criterion comment="nscd is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:104330"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-49.el5_5.6" test_ref="oval:org.mitre.oval:tst:104334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23010" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0661: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0661-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0661.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2240" ref_url="http://linux.oracle.com/cve/CVE-2010-2240.html" source="CVE"/>
        <description>The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment, as demonstrated by a memory-exhaustion attack against the X.Org X server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:33.660-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.386-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:08.328-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23010 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:17.567-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:10.260-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:104152"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:103541"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:103895"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:104084"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:104131"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:103894"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:104106"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:103962"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:103309"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:104242"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:104298"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.11.3.el5" test_ref="oval:org.mitre.oval:tst:104255"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23009" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0603: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0603-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0603.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:00.650-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.295-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:08.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23009 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.695-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:10.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:106711"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:107256"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:107197"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:107108"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.8.0.el5_9" test_ref="oval:org.mitre.oval:tst:106849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23008" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1646: libtool security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>libtool</product>
        </affected>
        <reference ref_id="ELSA-2009:1646-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1646.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3736" ref_url="http://linux.oracle.com/cve/CVE-2009-3736.html" source="CVE"/>
        <description>ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:33.531-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.231-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:08.081-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23008 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.503-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:10.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtool is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:103084"/>
          <criterion comment="libtool-ltdl is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:102628"/>
          <criterion comment="libtool-ltdl-devel is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:103362"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23007" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1116: perl-DBD-Pg security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference ref_id="ELSA-2012:1116-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1116.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1151" ref_url="http://linux.oracle.com/cve/CVE-2012-1151.html" source="CVE"/>
        <description>Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:21:57.104-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.163-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.982-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23007 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.916-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.950-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:47:28.397-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:47:28.397-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="perl-DBD-Pg is earlier than 0:1.49-4.el5_8" test_ref="oval:org.mitre.oval:tst:106606"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="perl-DBD-Pg is earlier than 0:2.15.1-4.el6_3" test_ref="oval:org.mitre.oval:tst:106698"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23006" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0044: pidgin security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2010:0044-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0044.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0013" ref_url="http://linux.oracle.com/cve/CVE-2010-0013.html" source="CVE"/>
        <description>Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122.  NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:47.216-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.086-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.870-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23006 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.913-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.850-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libpurple is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103540"/>
          <criterion comment="finch is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103447"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103654"/>
          <criterion comment="pidgin is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:102699"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103664"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103087"/>
          <criterion comment="finch-devel is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103520"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103691"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.5-1.el5" test_ref="oval:org.mitre.oval:tst:103383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23005" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0343: krb5 security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2010:0343-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0343.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0629" ref_url="http://linux.oracle.com/cve/CVE-2010-0629.html" source="CVE"/>
        <description>Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:42.200-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:07.015-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.753-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23005 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:13.795-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:103884"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:103537"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:103897"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:103620"/>
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:103956"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23004" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1361: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1361-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1361.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4193" ref_url="http://linux.oracle.com/cve/CVE-2012-4193.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:03.909-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:06.944-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.583-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23004 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.185-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.613-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:46:58.128-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:46:58.128-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:110798"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:111263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:110431"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:111079"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23003" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0061: gzip security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gzip</product>
        </affected>
        <reference ref_id="ELSA-2010:0061-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0061.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0001" ref_url="http://linux.oracle.com/cve/CVE-2010-0001.html" source="CVE"/>
        <description>Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:41.929-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:06.886-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.479-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23003 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:17.183-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.494-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="gzip is earlier than 0:1.3.5-11.el5_4.1" test_ref="oval:org.mitre.oval:tst:103478"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23002" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0002: PyXML security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>PyXML</product>
        </affected>
        <reference ref_id="ELSA-2010:0002-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0002.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3720" ref_url="http://linux.oracle.com/cve/CVE-2009-3720.html" source="CVE"/>
        <description>The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:55.827-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:06.829-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23002 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.905-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="PyXML is earlier than 0:0.8.4-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:103427"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23001" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0362: scsi-target-utils security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference ref_id="ELSA-2010:0362-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0362.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0743" ref_url="http://linux.oracle.com/cve/CVE-2010-0743.html" source="CVE"/>
        <description>Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:53.875-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:06.755-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.204-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23001 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:13.548-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="scsi-target-utils is earlier than 0:0.0-6.20091205snap.el5_5.2" test_ref="oval:org.mitre.oval:tst:103177"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23000" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0166: gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2010:0166-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0166.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2409" ref_url="http://linux.oracle.com/cve/CVE-2009-2409.html" source="CVE"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:58.253-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:06.658-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:07.135-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23000 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.454-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:103738"/>
          <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:103792"/>
          <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_4.8" test_ref="oval:org.mitre.oval:tst:103678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22999" version="29" class="patch">
      <metadata>
        <title>ELSA-2009:1548: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2009:1548-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1548.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2695" ref_url="http://linux.oracle.com/cve/CVE-2009-2695.html" source="CVE"/>
        <reference ref_id="CVE-2009-2908" ref_url="http://linux.oracle.com/cve/CVE-2009-2908.html" source="CVE"/>
        <reference ref_id="CVE-2009-3228" ref_url="http://linux.oracle.com/cve/CVE-2009-3228.html" source="CVE"/>
        <reference ref_id="CVE-2009-3286" ref_url="http://linux.oracle.com/cve/CVE-2009-3286.html" source="CVE"/>
        <reference ref_id="CVE-2009-3547" ref_url="http://linux.oracle.com/cve/CVE-2009-3547.html" source="CVE"/>
        <reference ref_id="CVE-2009-3613" ref_url="http://linux.oracle.com/cve/CVE-2009-3613.html" source="CVE"/>
        <description>The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of network traffic, as demonstrated by a flood ping.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:25.565-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:06.491-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:06.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22999 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:17.078-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:09.020-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103396"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103056"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103250"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103574"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103077"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103296"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:102592"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103554"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103373"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103525"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103379"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:103182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22998" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:0323: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2012:0323-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0323.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3607" ref_url="http://linux.oracle.com/cve/CVE-2011-3607.html" source="CVE"/>
        <reference ref_id="CVE-2011-3639" ref_url="http://linux.oracle.com/cve/CVE-2011-3639.html" source="CVE"/>
        <reference ref_id="CVE-2012-0031" ref_url="http://linux.oracle.com/cve/CVE-2012-0031.html" source="CVE"/>
        <reference ref_id="CVE-2012-0053" ref_url="http://linux.oracle.com/cve/CVE-2012-0053.html" source="CVE"/>
        <description>protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:57.086-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:06.374-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:06.626-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22998 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:13.462-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:08.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:105845"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:105161"/>
          <criterion comment="httpd is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:105578"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-63.el5_8.1" test_ref="oval:org.mitre.oval:tst:105403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22997" version="125" class="patch">
      <metadata>
        <title>ELSA-2010:0464: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2010:0464-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0464.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-4546" ref_url="http://linux.oracle.com/cve/CVE-2008-4546.html" source="CVE"/>
        <reference ref_id="CVE-2009-3793" ref_url="http://linux.oracle.com/cve/CVE-2009-3793.html" source="CVE"/>
        <reference ref_id="CVE-2010-1297" ref_url="http://linux.oracle.com/cve/CVE-2010-1297.html" source="CVE"/>
        <reference ref_id="CVE-2010-2160" ref_url="http://linux.oracle.com/cve/CVE-2010-2160.html" source="CVE"/>
        <reference ref_id="CVE-2010-2161" ref_url="http://linux.oracle.com/cve/CVE-2010-2161.html" source="CVE"/>
        <reference ref_id="CVE-2010-2162" ref_url="http://linux.oracle.com/cve/CVE-2010-2162.html" source="CVE"/>
        <reference ref_id="CVE-2010-2163" ref_url="http://linux.oracle.com/cve/CVE-2010-2163.html" source="CVE"/>
        <reference ref_id="CVE-2010-2164" ref_url="http://linux.oracle.com/cve/CVE-2010-2164.html" source="CVE"/>
        <reference ref_id="CVE-2010-2165" ref_url="http://linux.oracle.com/cve/CVE-2010-2165.html" source="CVE"/>
        <reference ref_id="CVE-2010-2166" ref_url="http://linux.oracle.com/cve/CVE-2010-2166.html" source="CVE"/>
        <reference ref_id="CVE-2010-2167" ref_url="http://linux.oracle.com/cve/CVE-2010-2167.html" source="CVE"/>
        <reference ref_id="CVE-2010-2169" ref_url="http://linux.oracle.com/cve/CVE-2010-2169.html" source="CVE"/>
        <reference ref_id="CVE-2010-2170" ref_url="http://linux.oracle.com/cve/CVE-2010-2170.html" source="CVE"/>
        <reference ref_id="CVE-2010-2171" ref_url="http://linux.oracle.com/cve/CVE-2010-2171.html" source="CVE"/>
        <reference ref_id="CVE-2010-2173" ref_url="http://linux.oracle.com/cve/CVE-2010-2173.html" source="CVE"/>
        <reference ref_id="CVE-2010-2174" ref_url="http://linux.oracle.com/cve/CVE-2010-2174.html" source="CVE"/>
        <reference ref_id="CVE-2010-2175" ref_url="http://linux.oracle.com/cve/CVE-2010-2175.html" source="CVE"/>
        <reference ref_id="CVE-2010-2176" ref_url="http://linux.oracle.com/cve/CVE-2010-2176.html" source="CVE"/>
        <reference ref_id="CVE-2010-2177" ref_url="http://linux.oracle.com/cve/CVE-2010-2177.html" source="CVE"/>
        <reference ref_id="CVE-2010-2178" ref_url="http://linux.oracle.com/cve/CVE-2010-2178.html" source="CVE"/>
        <reference ref_id="CVE-2010-2179" ref_url="http://linux.oracle.com/cve/CVE-2010-2179.html" source="CVE"/>
        <reference ref_id="CVE-2010-2180" ref_url="http://linux.oracle.com/cve/CVE-2010-2180.html" source="CVE"/>
        <reference ref_id="CVE-2010-2181" ref_url="http://linux.oracle.com/cve/CVE-2010-2181.html" source="CVE"/>
        <reference ref_id="CVE-2010-2182" ref_url="http://linux.oracle.com/cve/CVE-2010-2182.html" source="CVE"/>
        <reference ref_id="CVE-2010-2183" ref_url="http://linux.oracle.com/cve/CVE-2010-2183.html" source="CVE"/>
        <reference ref_id="CVE-2010-2184" ref_url="http://linux.oracle.com/cve/CVE-2010-2184.html" source="CVE"/>
        <reference ref_id="CVE-2010-2185" ref_url="http://linux.oracle.com/cve/CVE-2010-2185.html" source="CVE"/>
        <reference ref_id="CVE-2010-2186" ref_url="http://linux.oracle.com/cve/CVE-2010-2186.html" source="CVE"/>
        <reference ref_id="CVE-2010-2187" ref_url="http://linux.oracle.com/cve/CVE-2010-2187.html" source="CVE"/>
        <reference ref_id="CVE-2010-2188" ref_url="http://linux.oracle.com/cve/CVE-2010-2188.html" source="CVE"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:09.016-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:05.689-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:05.485-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22997 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:18.103-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:08.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="flash-plugin is earlier than 0:10.1-2.el5" test_ref="oval:org.mitre.oval:tst:103715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22996" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1236: xen security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference ref_id="ELSA-2012:1236-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1236.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3515" ref_url="http://linux.oracle.com/cve/CVE-2012-3515.html" source="CVE"/>
        <description>Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:35.891-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:05.628-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:05.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22996 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.417-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:08.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xen-libs is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:106743"/>
          <criterion comment="xen is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:106626"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-135.el5_8.5" test_ref="oval:org.mitre.oval:tst:105965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22995" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0475: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2010:0475-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0475.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1646" ref_url="http://linux.oracle.com/cve/CVE-2010-1646.html" source="CVE"/>
        <description>The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:53.705-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:05.573-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:05.280-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22995 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.975-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:08.044-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="sudo is earlier than 0:1.7.2p1-7.el5_5" test_ref="oval:org.mitre.oval:tst:103763"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22994" version="65" class="patch">
      <metadata>
        <title>ELSA-2010:0339: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2010:0339-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0339.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-0082" ref_url="http://linux.oracle.com/cve/CVE-2010-0082.html" source="CVE"/>
        <reference ref_id="CVE-2010-0084" ref_url="http://linux.oracle.com/cve/CVE-2010-0084.html" source="CVE"/>
        <reference ref_id="CVE-2010-0085" ref_url="http://linux.oracle.com/cve/CVE-2010-0085.html" source="CVE"/>
        <reference ref_id="CVE-2010-0088" ref_url="http://linux.oracle.com/cve/CVE-2010-0088.html" source="CVE"/>
        <reference ref_id="CVE-2010-0091" ref_url="http://linux.oracle.com/cve/CVE-2010-0091.html" source="CVE"/>
        <reference ref_id="CVE-2010-0092" ref_url="http://linux.oracle.com/cve/CVE-2010-0092.html" source="CVE"/>
        <reference ref_id="CVE-2010-0093" ref_url="http://linux.oracle.com/cve/CVE-2010-0093.html" source="CVE"/>
        <reference ref_id="CVE-2010-0094" ref_url="http://linux.oracle.com/cve/CVE-2010-0094.html" source="CVE"/>
        <reference ref_id="CVE-2010-0095" ref_url="http://linux.oracle.com/cve/CVE-2010-0095.html" source="CVE"/>
        <reference ref_id="CVE-2010-0837" ref_url="http://linux.oracle.com/cve/CVE-2010-0837.html" source="CVE"/>
        <reference ref_id="CVE-2010-0838" ref_url="http://linux.oracle.com/cve/CVE-2010-0838.html" source="CVE"/>
        <reference ref_id="CVE-2010-0840" ref_url="http://linux.oracle.com/cve/CVE-2010-0840.html" source="CVE"/>
        <reference ref_id="CVE-2010-0845" ref_url="http://linux.oracle.com/cve/CVE-2010-0845.html" source="CVE"/>
        <reference ref_id="CVE-2010-0847" ref_url="http://linux.oracle.com/cve/CVE-2010-0847.html" source="CVE"/>
        <reference ref_id="CVE-2010-0848" ref_url="http://linux.oracle.com/cve/CVE-2010-0848.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:41.479-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:05.272-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:05.179-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22994 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:17.690-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:07.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:103831"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:103821"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:103441"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:103933"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:103828"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22993" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0165: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>nspr</product>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2010:0165-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0165.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:48.483-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:05.158-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:05.099-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22993 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.095-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:07.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr-devel is earlier than 0:4.8.4-1.el5_4" test_ref="oval:org.mitre.oval:tst:103787"/>
          <criterion comment="nspr is earlier than 0:4.8.4-1.el5_4" test_ref="oval:org.mitre.oval:tst:103795"/>
          <criterion comment="nss is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:103585"/>
          <criterion comment="nss-tools is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:103402"/>
          <criterion comment="nss-devel is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:103430"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:103770"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22992" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0603: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>gnupg2</product>
        </affected>
        <reference ref_id="ELSA-2010:0603-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0603.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2547" ref_url="http://linux.oracle.com/cve/CVE-2010-2547.html" source="CVE"/>
        <description>Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:51.949-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:05.088-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:05.002-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22992 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.839-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:07.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="gnupg2 is earlier than 0:2.0.10-3.el5_5.1" test_ref="oval:org.mitre.oval:tst:104160"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22991" version="73" class="patch">
      <metadata>
        <title>ELSA-2010:0503: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2010:0503-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0503.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1240" ref_url="http://linux.oracle.com/cve/CVE-2010-1240.html" source="CVE"/>
        <reference ref_id="CVE-2010-1285" ref_url="http://linux.oracle.com/cve/CVE-2010-1285.html" source="CVE"/>
        <reference ref_id="CVE-2010-1295" ref_url="http://linux.oracle.com/cve/CVE-2010-1295.html" source="CVE"/>
        <reference ref_id="CVE-2010-1297" ref_url="http://linux.oracle.com/cve/CVE-2010-1297.html" source="CVE"/>
        <reference ref_id="CVE-2010-2168" ref_url="http://linux.oracle.com/cve/CVE-2010-2168.html" source="CVE"/>
        <reference ref_id="CVE-2010-2201" ref_url="http://linux.oracle.com/cve/CVE-2010-2201.html" source="CVE"/>
        <reference ref_id="CVE-2010-2202" ref_url="http://linux.oracle.com/cve/CVE-2010-2202.html" source="CVE"/>
        <reference ref_id="CVE-2010-2203" ref_url="http://linux.oracle.com/cve/CVE-2010-2203.html" source="CVE"/>
        <reference ref_id="CVE-2010-2204" ref_url="http://linux.oracle.com/cve/CVE-2010-2204.html" source="CVE"/>
        <reference ref_id="CVE-2010-2205" ref_url="http://linux.oracle.com/cve/CVE-2010-2205.html" source="CVE"/>
        <reference ref_id="CVE-2010-2206" ref_url="http://linux.oracle.com/cve/CVE-2010-2206.html" source="CVE"/>
        <reference ref_id="CVE-2010-2207" ref_url="http://linux.oracle.com/cve/CVE-2010-2207.html" source="CVE"/>
        <reference ref_id="CVE-2010-2208" ref_url="http://linux.oracle.com/cve/CVE-2010-2208.html" source="CVE"/>
        <reference ref_id="CVE-2010-2209" ref_url="http://linux.oracle.com/cve/CVE-2010-2209.html" source="CVE"/>
        <reference ref_id="CVE-2010-2210" ref_url="http://linux.oracle.com/cve/CVE-2010-2210.html" source="CVE"/>
        <reference ref_id="CVE-2010-2211" ref_url="http://linux.oracle.com/cve/CVE-2010-2211.html" source="CVE"/>
        <reference ref_id="CVE-2010-2212" ref_url="http://linux.oracle.com/cve/CVE-2010-2212.html" source="CVE"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2211.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:03.504-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:04.753-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:04.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22991 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.117-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:07.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="acroread-plugin is earlier than 0:9.3.3-1.el5" test_ref="oval:org.mitre.oval:tst:103989"/>
          <criterion comment="acroread is earlier than 0:9.3.3-1.el5" test_ref="oval:org.mitre.oval:tst:104063"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22989" version="57" class="patch">
      <metadata>
        <title>ELSA-2011:0017: Oracle Linux 5.x.6 kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0017-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0017.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3296" ref_url="http://linux.oracle.com/cve/CVE-2010-3296.html" source="CVE"/>
        <reference ref_id="CVE-2010-3877" ref_url="http://linux.oracle.com/cve/CVE-2010-3877.html" source="CVE"/>
        <reference ref_id="CVE-2010-4072" ref_url="http://linux.oracle.com/cve/CVE-2010-4072.html" source="CVE"/>
        <reference ref_id="CVE-2010-4073" ref_url="http://linux.oracle.com/cve/CVE-2010-4073.html" source="CVE"/>
        <reference ref_id="CVE-2010-4075" ref_url="http://linux.oracle.com/cve/CVE-2010-4075.html" source="CVE"/>
        <reference ref_id="CVE-2010-4080" ref_url="http://linux.oracle.com/cve/CVE-2010-4080.html" source="CVE"/>
        <reference ref_id="CVE-2010-4081" ref_url="http://linux.oracle.com/cve/CVE-2010-4081.html" source="CVE"/>
        <reference ref_id="CVE-2010-4158" ref_url="http://linux.oracle.com/cve/CVE-2010-4158.html" source="CVE"/>
        <reference ref_id="CVE-2010-4238" ref_url="http://linux.oracle.com/cve/CVE-2010-4238.html" source="CVE"/>
        <reference ref_id="CVE-2010-4243" ref_url="http://linux.oracle.com/cve/CVE-2010-4243.html" source="CVE"/>
        <reference ref_id="CVE-2010-4255" ref_url="http://linux.oracle.com/cve/CVE-2010-4255.html" source="CVE"/>
        <reference ref_id="CVE-2010-4263" ref_url="http://linux.oracle.com/cve/CVE-2010-4263.html" source="CVE"/>
        <reference ref_id="CVE-2010-4343" ref_url="http://linux.oracle.com/cve/CVE-2010-4343.html" source="CVE"/>
        <description>drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port data structure, which allows local users to cause a denial of service (system crash) via read operations on an fc_host statistics file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:04.871-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:04.413-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:03.576-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22989 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.729-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:06.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104476"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104228"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104650"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104627"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:103772"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104400"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104603"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104403"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104600"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104444"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104562"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.el5" test_ref="oval:org.mitre.oval:tst:104506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22988" version="81" class="patch">
      <metadata>
        <title>ELSA-2010:0743: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2010:0743-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0743.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2883" ref_url="http://linux.oracle.com/cve/CVE-2010-2883.html" source="CVE"/>
        <reference ref_id="CVE-2010-2884" ref_url="http://linux.oracle.com/cve/CVE-2010-2884.html" source="CVE"/>
        <reference ref_id="CVE-2010-2887" ref_url="http://linux.oracle.com/cve/CVE-2010-2887.html" source="CVE"/>
        <reference ref_id="CVE-2010-2889" ref_url="http://linux.oracle.com/cve/CVE-2010-2889.html" source="CVE"/>
        <reference ref_id="CVE-2010-2890" ref_url="http://linux.oracle.com/cve/CVE-2010-2890.html" source="CVE"/>
        <reference ref_id="CVE-2010-3619" ref_url="http://linux.oracle.com/cve/CVE-2010-3619.html" source="CVE"/>
        <reference ref_id="CVE-2010-3620" ref_url="http://linux.oracle.com/cve/CVE-2010-3620.html" source="CVE"/>
        <reference ref_id="CVE-2010-3621" ref_url="http://linux.oracle.com/cve/CVE-2010-3621.html" source="CVE"/>
        <reference ref_id="CVE-2010-3622" ref_url="http://linux.oracle.com/cve/CVE-2010-3622.html" source="CVE"/>
        <reference ref_id="CVE-2010-3625" ref_url="http://linux.oracle.com/cve/CVE-2010-3625.html" source="CVE"/>
        <reference ref_id="CVE-2010-3626" ref_url="http://linux.oracle.com/cve/CVE-2010-3626.html" source="CVE"/>
        <reference ref_id="CVE-2010-3627" ref_url="http://linux.oracle.com/cve/CVE-2010-3627.html" source="CVE"/>
        <reference ref_id="CVE-2010-3628" ref_url="http://linux.oracle.com/cve/CVE-2010-3628.html" source="CVE"/>
        <reference ref_id="CVE-2010-3629" ref_url="http://linux.oracle.com/cve/CVE-2010-3629.html" source="CVE"/>
        <reference ref_id="CVE-2010-3630" ref_url="http://linux.oracle.com/cve/CVE-2010-3630.html" source="CVE"/>
        <reference ref_id="CVE-2010-3632" ref_url="http://linux.oracle.com/cve/CVE-2010-3632.html" source="CVE"/>
        <reference ref_id="CVE-2010-3656" ref_url="http://linux.oracle.com/cve/CVE-2010-3656.html" source="CVE"/>
        <reference ref_id="CVE-2010-3657" ref_url="http://linux.oracle.com/cve/CVE-2010-3657.html" source="CVE"/>
        <reference ref_id="CVE-2010-3658" ref_url="http://linux.oracle.com/cve/CVE-2010-3658.html" source="CVE"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, and CVE-2010-3632.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:21.334-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:04.053-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:02.826-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22988 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:17.933-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:06.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="acroread-plugin is earlier than 0:9.4.0-1.el5" test_ref="oval:org.mitre.oval:tst:103981"/>
          <criterion comment="acroread is earlier than 0:9.4.0-1.el5" test_ref="oval:org.mitre.oval:tst:104253"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22987" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0054: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2010:0054-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0054.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2409" ref_url="http://linux.oracle.com/cve/CVE-2009-2409.html" source="CVE"/>
        <reference ref_id="CVE-2009-4355" ref_url="http://linux.oracle.com/cve/CVE-2009-4355.html" source="CVE"/>
        <description>Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:55.606-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.967-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:02.720-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22987 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.374-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:06.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:103544"/>
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:103137"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:102954"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22986" version="49" class="patch">
      <metadata>
        <title>ELSA-2009:1530: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>nspr</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2009:1530-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1530.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-1563" ref_url="http://linux.oracle.com/cve/CVE-2009-1563.html" source="CVE"/>
        <reference ref_id="CVE-2009-3274" ref_url="http://linux.oracle.com/cve/CVE-2009-3274.html" source="CVE"/>
        <reference ref_id="CVE-2009-3370" ref_url="http://linux.oracle.com/cve/CVE-2009-3370.html" source="CVE"/>
        <reference ref_id="CVE-2009-3372" ref_url="http://linux.oracle.com/cve/CVE-2009-3372.html" source="CVE"/>
        <reference ref_id="CVE-2009-3373" ref_url="http://linux.oracle.com/cve/CVE-2009-3373.html" source="CVE"/>
        <reference ref_id="CVE-2009-3374" ref_url="http://linux.oracle.com/cve/CVE-2009-3374.html" source="CVE"/>
        <reference ref_id="CVE-2009-3375" ref_url="http://linux.oracle.com/cve/CVE-2009-3375.html" source="CVE"/>
        <reference ref_id="CVE-2009-3376" ref_url="http://linux.oracle.com/cve/CVE-2009-3376.html" source="CVE"/>
        <reference ref_id="CVE-2009-3380" ref_url="http://linux.oracle.com/cve/CVE-2009-3380.html" source="CVE"/>
        <reference ref_id="CVE-2009-3382" ref_url="http://linux.oracle.com/cve/CVE-2009-3382.html" source="CVE"/>
        <reference ref_id="CVE-2009-3384" ref_url="http://linux.oracle.com/cve/CVE-2009-3384.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:39.869-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.733-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:02.265-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22986 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.588-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:05.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:102816"/>
          <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:102805"/>
          <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:103202"/>
          <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:103523"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:103388"/>
          <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:103274"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22985" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0115: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2010:0115-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0115.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0277" ref_url="http://linux.oracle.com/cve/CVE-2010-0277.html" source="CVE"/>
        <reference ref_id="CVE-2010-0420" ref_url="http://linux.oracle.com/cve/CVE-2010-0420.html" source="CVE"/>
        <reference ref_id="CVE-2010-0423" ref_url="http://linux.oracle.com/cve/CVE-2010-0423.html" source="CVE"/>
        <description>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:44.461-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.620-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:02.072-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22985 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.279-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:05.265-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103671"/>
          <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103602"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103234"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103630"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103467"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103594"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:102809"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103531"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:103589"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22984" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0317: libpng security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference ref_id="ELSA-2012:0317-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0317.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3026" ref_url="http://linux.oracle.com/cve/CVE-2011-3026.html" source="CVE"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:53.934-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.546-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:01.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22984 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:17.805-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:05.145-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:46:22.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:46:22.976-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-static is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:105872"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:105016"/>
            <criterion comment="libpng is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:105959"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:105861"/>
            <criterion comment="libpng is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:106002"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22983" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:1449: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1449-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1449.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0333" ref_url="http://linux.oracle.com/cve/CVE-2013-0333.html" source="CVE"/>
        <reference ref_id="CVE-2013-4299" ref_url="http://linux.oracle.com/cve/CVE-2013-4299.html" source="CVE"/>
        <reference ref_id="CVE-2013-4345" ref_url="http://linux.oracle.com/cve/CVE-2013-4345.html" source="CVE"/>
        <reference ref_id="CVE-2013-4368" ref_url="http://linux.oracle.com/cve/CVE-2013-4368.html" source="CVE"/>
        <description>The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:27.716-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.407-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:01.705-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22983 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:13.898-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:04.894-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107589"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107493"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107294"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107434"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107697"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107601"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107645"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107734"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107476"/>
          <criterion comment="kernel is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107822"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107211"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-371.1.2.el5" test_ref="oval:org.mitre.oval:tst:107616"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22982" version="13" class="patch">
      <metadata>
        <title>ELSA-2009:1459: cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference ref_id="ELSA-2009:1459-04" ref_url="http://linux.oracle.com/errata/ELSA-2009-1459.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2632" ref_url="http://linux.oracle.com/cve/CVE-2009-2632.html" source="CVE"/>
        <reference ref_id="CVE-2009-3235" ref_url="http://linux.oracle.com/cve/CVE-2009-3235.html" source="CVE"/>
        <description>Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:38.395-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.321-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:01.552-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22982 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:13.708-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:04.731-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:102470"/>
          <criterion comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:103384"/>
          <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:103221"/>
          <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_4.3" test_ref="oval:org.mitre.oval:tst:103267"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22981" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1265: libxslt security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libxslt</product>
        </affected>
        <reference ref_id="ELSA-2012:1265-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-1265.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1202" ref_url="http://linux.oracle.com/cve/CVE-2011-1202.html" source="CVE"/>
        <reference ref_id="CVE-2011-3970" ref_url="http://linux.oracle.com/cve/CVE-2011-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-2825" ref_url="http://linux.oracle.com/cve/CVE-2012-2825.html" source="CVE"/>
        <reference ref_id="CVE-2012-2870" ref_url="http://linux.oracle.com/cve/CVE-2012-2870.html" source="CVE"/>
        <reference ref_id="CVE-2012-2871" ref_url="http://linux.oracle.com/cve/CVE-2012-2871.html" source="CVE"/>
        <reference ref_id="CVE-2012-2893" ref_url="http://linux.oracle.com/cve/CVE-2012-2893.html" source="CVE"/>
        <description>Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:44.488-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.153-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:01.261-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22981 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.325-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:04.336-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:45:42.400-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:45:42.400-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:106717"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:106749"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:106142"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxslt-devel is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:106437"/>
            <criterion comment="libxslt is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:106644"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:106853"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22980" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1428: xmlsec1 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xmlsec1</product>
        </affected>
        <reference ref_id="ELSA-2009:1428-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1428.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-0217" ref_url="http://linux.oracle.com/cve/CVE-2009-0217.html" source="CVE"/>
        <description>The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:35.210-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:03.051-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:01.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22980 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.587-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:04.200-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xmlsec1-nss-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:102966"/>
          <criterion comment="xmlsec1-openssl is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:102710"/>
          <criterion comment="xmlsec1-nss is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:103213"/>
          <criterion comment="xmlsec1-gnutls is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:103410"/>
          <criterion comment="xmlsec1 is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:103078"/>
          <criterion comment="xmlsec1-gnutls-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:103377"/>
          <criterion comment="xmlsec1-openssl-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:103286"/>
          <criterion comment="xmlsec1-devel is earlier than 0:1.2.9-8.1.1" test_ref="oval:org.mitre.oval:tst:103251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22979" version="65" class="patch">
      <metadata>
        <title>ELSA-2009:1584: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2009:1584-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1584.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2409" ref_url="http://linux.oracle.com/cve/CVE-2009-2409.html" source="CVE"/>
        <reference ref_id="CVE-2009-3728" ref_url="http://linux.oracle.com/cve/CVE-2009-3728.html" source="CVE"/>
        <reference ref_id="CVE-2009-3869" ref_url="http://linux.oracle.com/cve/CVE-2009-3869.html" source="CVE"/>
        <reference ref_id="CVE-2009-3871" ref_url="http://linux.oracle.com/cve/CVE-2009-3871.html" source="CVE"/>
        <reference ref_id="CVE-2009-3873" ref_url="http://linux.oracle.com/cve/CVE-2009-3873.html" source="CVE"/>
        <reference ref_id="CVE-2009-3874" ref_url="http://linux.oracle.com/cve/CVE-2009-3874.html" source="CVE"/>
        <reference ref_id="CVE-2009-3875" ref_url="http://linux.oracle.com/cve/CVE-2009-3875.html" source="CVE"/>
        <reference ref_id="CVE-2009-3876" ref_url="http://linux.oracle.com/cve/CVE-2009-3876.html" source="CVE"/>
        <reference ref_id="CVE-2009-3877" ref_url="http://linux.oracle.com/cve/CVE-2009-3877.html" source="CVE"/>
        <reference ref_id="CVE-2009-3879" ref_url="http://linux.oracle.com/cve/CVE-2009-3879.html" source="CVE"/>
        <reference ref_id="CVE-2009-3880" ref_url="http://linux.oracle.com/cve/CVE-2009-3880.html" source="CVE"/>
        <reference ref_id="CVE-2009-3881" ref_url="http://linux.oracle.com/cve/CVE-2009-3881.html" source="CVE"/>
        <reference ref_id="CVE-2009-3882" ref_url="http://linux.oracle.com/cve/CVE-2009-3882.html" source="CVE"/>
        <reference ref_id="CVE-2009-3883" ref_url="http://linux.oracle.com/cve/CVE-2009-3883.html" source="CVE"/>
        <reference ref_id="CVE-2009-3884" ref_url="http://linux.oracle.com/cve/CVE-2009-3884.html" source="CVE"/>
        <description>The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:27.215-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:02.846-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:00.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22979 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.558-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:04.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:103489"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:103210"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:103411"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:103163"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:103186"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22977" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0336: tomcat5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>tomcat5</product>
        </affected>
        <reference ref_id="ELSA-2011:0336-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0336.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:19.570-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:02.662-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:00.752-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22977 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.412-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:03.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104734"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104761"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104290"/>
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104682"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104702"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104939"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104772"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104828"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104893"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104875"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.17.el5_6" test_ref="oval:org.mitre.oval:tst:104155"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22976" version="29" class="patch">
      <metadata>
        <title>ELSA-2010:0839: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0839-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0839.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3066" ref_url="http://linux.oracle.com/cve/CVE-2010-3066.html" source="CVE"/>
        <reference ref_id="CVE-2010-3067" ref_url="http://linux.oracle.com/cve/CVE-2010-3067.html" source="CVE"/>
        <reference ref_id="CVE-2010-3078" ref_url="http://linux.oracle.com/cve/CVE-2010-3078.html" source="CVE"/>
        <reference ref_id="CVE-2010-3086" ref_url="http://linux.oracle.com/cve/CVE-2010-3086.html" source="CVE"/>
        <reference ref_id="CVE-2010-3448" ref_url="http://linux.oracle.com/cve/CVE-2010-3448.html" source="CVE"/>
        <reference ref_id="CVE-2010-3477" ref_url="http://linux.oracle.com/cve/CVE-2010-3477.html" source="CVE"/>
        <description>The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:21.913-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:02.499-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:00.449-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22976 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:13.275-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:03.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:103796"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:103891"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104508"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:103995"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104023"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104171"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:103672"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104045"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104488"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104343"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104461"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.26.1.el5" test_ref="oval:org.mitre.oval:tst:104314"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22975" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1536: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2009:1536-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1536.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3615" ref_url="http://linux.oracle.com/cve/CVE-2009-3615.html" source="CVE"/>
        <description>The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:32.310-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:02.426-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:03:00.315-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22975 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:14.129-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:03.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="finch is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:103437"/>
          <criterion comment="libpurple is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:103432"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:103545"/>
          <criterion comment="pidgin is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:103239"/>
          <criterion comment="finch-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:102751"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:103318"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:103129"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:102896"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:103420"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22974" version="37" class="patch">
      <metadata>
        <title>ELSA-2009:1582: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2009:1582-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1582.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2625" ref_url="http://linux.oracle.com/cve/CVE-2009-2625.html" source="CVE"/>
        <reference ref_id="CVE-2009-2670" ref_url="http://linux.oracle.com/cve/CVE-2009-2670.html" source="CVE"/>
        <reference ref_id="CVE-2009-2671" ref_url="http://linux.oracle.com/cve/CVE-2009-2671.html" source="CVE"/>
        <reference ref_id="CVE-2009-2672" ref_url="http://linux.oracle.com/cve/CVE-2009-2672.html" source="CVE"/>
        <reference ref_id="CVE-2009-2673" ref_url="http://linux.oracle.com/cve/CVE-2009-2673.html" source="CVE"/>
        <reference ref_id="CVE-2009-2674" ref_url="http://linux.oracle.com/cve/CVE-2009-2674.html" source="CVE"/>
        <reference ref_id="CVE-2009-2675" ref_url="http://linux.oracle.com/cve/CVE-2009-2675.html" source="CVE"/>
        <reference ref_id="CVE-2009-2676" ref_url="http://linux.oracle.com/cve/CVE-2009-2676.html" source="CVE"/>
        <description>Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:31.485-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:02.234-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:59.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22974 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:17.372-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:02.846-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103549"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103516"/>
          <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103534"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103124"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:102676"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:102915"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103143"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.6-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:103558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22973" version="26" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1341: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1341-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1341.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2372" ref_url="http://linux.oracle.com/cve/CVE-2011-2372.html" source="CVE"/>
        <reference ref_id="CVE-2011-2995" ref_url="http://linux.oracle.com/cve/CVE-2011-2995.html" source="CVE"/>
        <reference ref_id="CVE-2011-2998" ref_url="http://linux.oracle.com/cve/CVE-2011-2998.html" source="CVE"/>
        <reference ref_id="CVE-2011-2999" ref_url="http://linux.oracle.com/cve/CVE-2011-2999.html" source="CVE"/>
        <reference ref_id="CVE-2011-3000" ref_url="http://linux.oracle.com/cve/CVE-2011-3000.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:25.754-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:02.084-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:59.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22973 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.687-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:02.487-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:44:58.326-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:44:58.326-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:105272"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:105242"/>
            <criterion comment="firefox is earlier than 0:3.6.23-2.el5_7" test_ref="oval:org.mitre.oval:tst:105338"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:3.6.23-2.el6_1" test_ref="oval:org.mitre.oval:tst:105219"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105300"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105080"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22972" version="45" class="patch">
      <metadata>
        <title>ELSA-2009:1643: java-1.4.2-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.4.2-ibm</product>
        </affected>
        <reference ref_id="ELSA-2009:1643-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1643.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3867" ref_url="http://linux.oracle.com/cve/CVE-2009-3867.html" source="CVE"/>
        <reference ref_id="CVE-2009-3868" ref_url="http://linux.oracle.com/cve/CVE-2009-3868.html" source="CVE"/>
        <reference ref_id="CVE-2009-3869" ref_url="http://linux.oracle.com/cve/CVE-2009-3869.html" source="CVE"/>
        <reference ref_id="CVE-2009-3871" ref_url="http://linux.oracle.com/cve/CVE-2009-3871.html" source="CVE"/>
        <reference ref_id="CVE-2009-3872" ref_url="http://linux.oracle.com/cve/CVE-2009-3872.html" source="CVE"/>
        <reference ref_id="CVE-2009-3873" ref_url="http://linux.oracle.com/cve/CVE-2009-3873.html" source="CVE"/>
        <reference ref_id="CVE-2009-3874" ref_url="http://linux.oracle.com/cve/CVE-2009-3874.html" source="CVE"/>
        <reference ref_id="CVE-2009-3875" ref_url="http://linux.oracle.com/cve/CVE-2009-3875.html" source="CVE"/>
        <reference ref_id="CVE-2009-3876" ref_url="http://linux.oracle.com/cve/CVE-2009-3876.html" source="CVE"/>
        <reference ref_id="CVE-2009-3877" ref_url="http://linux.oracle.com/cve/CVE-2009-3877.html" source="CVE"/>
        <description>Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:29.724-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:01.828-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:59.472-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22972 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.801-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:02.366-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103342"/>
          <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:102945"/>
          <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:102847"/>
          <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103500"/>
          <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:102965"/>
          <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:102901"/>
          <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103533"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22971" version="46" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0820: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0820-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0820.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0801" ref_url="http://linux.oracle.com/cve/CVE-2013-0801.html" source="CVE"/>
        <reference ref_id="CVE-2013-1670" ref_url="http://linux.oracle.com/cve/CVE-2013-1670.html" source="CVE"/>
        <reference ref_id="CVE-2013-1674" ref_url="http://linux.oracle.com/cve/CVE-2013-1674.html" source="CVE"/>
        <reference ref_id="CVE-2013-1675" ref_url="http://linux.oracle.com/cve/CVE-2013-1675.html" source="CVE"/>
        <reference ref_id="CVE-2013-1676" ref_url="http://linux.oracle.com/cve/CVE-2013-1676.html" source="CVE"/>
        <reference ref_id="CVE-2013-1677" ref_url="http://linux.oracle.com/cve/CVE-2013-1677.html" source="CVE"/>
        <reference ref_id="CVE-2013-1678" ref_url="http://linux.oracle.com/cve/CVE-2013-1678.html" source="CVE"/>
        <reference ref_id="CVE-2013-1679" ref_url="http://linux.oracle.com/cve/CVE-2013-1679.html" source="CVE"/>
        <reference ref_id="CVE-2013-1680" ref_url="http://linux.oracle.com/cve/CVE-2013-1680.html" source="CVE"/>
        <reference ref_id="CVE-2013-1681" ref_url="http://linux.oracle.com/cve/CVE-2013-1681.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:43.071-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:01.595-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:58.814-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22971 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:16.804-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:01.840-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:44:14.368-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:44:14.368-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:17.0.6-1.el6_4" test_ref="oval:org.mitre.oval:tst:107200"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:107448"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:107415"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:107385"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:106545"/>
            <criterion comment="firefox is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:107360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22970" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1207: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2012:1207-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1207.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3480" ref_url="http://linux.oracle.com/cve/CVE-2012-3480.html" source="CVE"/>
        <description>Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:34.466-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:01.525-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:58.676-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22970 - optimisation of Oracle Linux content" date="2014-05-05T17:55:00.751-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:57:15.227-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:01.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nscd is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:106815"/>
          <criterion comment="glibc-utils is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:106173"/>
          <criterion comment="glibc-devel is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:106479"/>
          <criterion comment="glibc-common is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:106160"/>
          <criterion comment="glibc is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:106678"/>
          <criterion comment="glibc-headers is earlier than 0:2.5-81.el5_8.7" test_ref="oval:org.mitre.oval:tst:106512"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22968" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1339: rgmanager security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>rgmanager</product>
        </affected>
        <reference ref_id="ELSA-2009:1339-02" ref_url="http://linux.oracle.com/errata/ELSA-2009-1339.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-6552" ref_url="http://linux.oracle.com/cve/CVE-2008-6552.html" source="CVE"/>
        <description>Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:43.654-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:01.385-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:58.455-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22968 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:32.258-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:54.089-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="rgmanager is earlier than 0:2.0.52-1.el5" test_ref="oval:org.mitre.oval:tst:103171"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22967" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:1323: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1323-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-1323.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2319" ref_url="http://linux.oracle.com/cve/CVE-2012-2319.html" source="CVE"/>
        <reference ref_id="CVE-2012-3412" ref_url="http://linux.oracle.com/cve/CVE-2012-3412.html" source="CVE"/>
        <reference ref_id="CVE-2012-3430" ref_url="http://linux.oracle.com/cve/CVE-2012-3430.html" source="CVE"/>
        <reference ref_id="CVE-2012-3510" ref_url="http://linux.oracle.com/cve/CVE-2012-3510.html" source="CVE"/>
        <description>Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:38.691-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:01.261-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:58.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22967 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:48.854-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:01.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-doc is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106139"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106861"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106687"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106900"/>
          <criterion comment="kernel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106700"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106782"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106869"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106867"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106638"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106858"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106985"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-308.16.1.el5" test_ref="oval:org.mitre.oval:tst:106902"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22966" version="22" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0737: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference ref_id="ELSA-2013:0737-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0737.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1845" ref_url="http://linux.oracle.com/cve/CVE-2013-1845.html" source="CVE"/>
        <reference ref_id="CVE-2013-1846" ref_url="http://linux.oracle.com/cve/CVE-2013-1846.html" source="CVE"/>
        <reference ref_id="CVE-2013-1847" ref_url="http://linux.oracle.com/cve/CVE-2013-1847.html" source="CVE"/>
        <reference ref_id="CVE-2013-1849" ref_url="http://linux.oracle.com/cve/CVE-2013-1849.html" source="CVE"/>
        <description>The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:41.690-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:01.132-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:57.927-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22966 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:47.631-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:00.930-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:43:30.498-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:43:30.498-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107176"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107288"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107441"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107234"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107183"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107404"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107336"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107213"/>
            <criterion comment="subversion is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:107116"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:107237"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:107299"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:107350"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:107060"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:106797"/>
            <criterion comment="subversion is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:107316"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22965" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1811: netpbm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>netpbm</product>
        </affected>
        <reference ref_id="ELSA-2011:1811-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1811.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4274" ref_url="http://linux.oracle.com/cve/CVE-2009-4274.html" source="CVE"/>
        <reference ref_id="CVE-2011-4516" ref_url="http://linux.oracle.com/cve/CVE-2011-4516.html" source="CVE"/>
        <reference ref_id="CVE-2011-4517" ref_url="http://linux.oracle.com/cve/CVE-2011-4517.html" source="CVE"/>
        <description>The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:39.570-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:00.992-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:57.724-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22965 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:50.156-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:00.706-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="netpbm-progs is earlier than 0:10.35.58-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:105213"/>
          <criterion comment="netpbm-devel is earlier than 0:10.35.58-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:105573"/>
          <criterion comment="netpbm is earlier than 0:10.35.58-8.el5_7.3" test_ref="oval:org.mitre.oval:tst:105548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22964" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0788: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2010:0788-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0788.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1624" ref_url="http://linux.oracle.com/cve/CVE-2010-1624.html" source="CVE"/>
        <reference ref_id="CVE-2010-3711" ref_url="http://linux.oracle.com/cve/CVE-2010-3711.html" source="CVE"/>
        <description>libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:18.228-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:00.895-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:57.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22964 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:47.762-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:00.535-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104309"/>
          <criterion comment="finch is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104040"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104372"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104348"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104386"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104425"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104233"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104402"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_5" test_ref="oval:org.mitre.oval:tst:104318"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22963" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0599: xen security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>xen</product>
        </affected>
        <reference ref_id="ELSA-2013:0599-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0599.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6075" ref_url="http://linux.oracle.com/cve/CVE-2012-6075.html" source="CVE"/>
        <description>Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:54.538-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:00.829-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:57.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22963 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:52.688-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:00.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xen-libs is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:107180"/>
          <criterion comment="xen is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:107163"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-142.el5_9.2" test_ref="oval:org.mitre.oval:tst:107303"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22962" version="73" class="patch">
      <metadata>
        <title>ELSA-2010:0768: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2010:0768-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0768.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3554" ref_url="http://linux.oracle.com/cve/CVE-2010-3554.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3561" ref_url="http://linux.oracle.com/cve/CVE-2010-3561.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3564" ref_url="http://linux.oracle.com/cve/CVE-2010-3564.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3567" ref_url="http://linux.oracle.com/cve/CVE-2010-3567.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3573" ref_url="http://linux.oracle.com/cve/CVE-2010-3573.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:16.007-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:00.498-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:57.284-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22962 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:52.271-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:03:00.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:104166"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:104354"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:103775"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:103936"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.16.b17.el5" test_ref="oval:org.mitre.oval:tst:104217"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22960" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0632: qspice-client security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>qspice-client</product>
        </affected>
        <reference ref_id="ELSA-2010:0632-03" ref_url="http://linux.oracle.com/errata/ELSA-2010-0632.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2792" ref_url="http://linux.oracle.com/cve/CVE-2010-2792.html" source="CVE"/>
        <description>Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:06.966-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:00.031-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:56.581-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22960 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:48.620-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:59.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="qspice-client is earlier than 0:0.3.0-4.el5_5" test_ref="oval:org.mitre.oval:tst:104159"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22959" version="17" class="patch">
      <metadata>
        <title>ELSA-2009:1504: poppler security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>poppler</product>
        </affected>
        <reference ref_id="ELSA-2009:1504-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1504.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3603" ref_url="http://linux.oracle.com/cve/CVE-2009-3603.html" source="CVE"/>
        <reference ref_id="CVE-2009-3608" ref_url="http://linux.oracle.com/cve/CVE-2009-3608.html" source="CVE"/>
        <reference ref_id="CVE-2009-3609" ref_url="http://linux.oracle.com/cve/CVE-2009-3609.html" source="CVE"/>
        <description>Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:29.164-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:59.839-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:56.472-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22959 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:53.282-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:59.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:103366"/>
          <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:103249"/>
          <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:103481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22958" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0129: cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>cups</product>
        </affected>
        <reference ref_id="ELSA-2010:0129-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0129.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0302" ref_url="http://linux.oracle.com/cve/CVE-2010-0302.html" source="CVE"/>
        <description>Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:58.500-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:59.738-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:56.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22958 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:49.170-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:59.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:103727"/>
          <criterion comment="cups-devel is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:103712"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:103780"/>
          <criterion comment="cups is earlier than 1:1.3.7-11.el5_4.6" test_ref="oval:org.mitre.oval:tst:103697"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22957" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0163: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0163-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0163.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4526" ref_url="http://linux.oracle.com/cve/CVE-2010-4526.html" source="CVE"/>
        <description>Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list corruption, related to the sctp_wait_for_connect function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:15.272-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:59.643-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:56.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22957 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:48.011-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:59.029-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104566"/>
          <criterion comment="kernel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104649"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104608"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104641"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104568"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104511"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104548"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104498"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104446"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104583"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104666"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-238.1.1.el5" test_ref="oval:org.mitre.oval:tst:104287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22956" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0108: NetworkManager security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>NetworkManager</product>
        </affected>
        <reference ref_id="ELSA-2010:0108-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0108.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4144" ref_url="http://linux.oracle.com/cve/CVE-2009-4144.html" source="CVE"/>
        <reference ref_id="CVE-2009-4145" ref_url="http://linux.oracle.com/cve/CVE-2009-4145.html" source="CVE"/>
        <description>nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:48.957-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:59.461-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:56.105-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22956 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:53.060-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:58.859-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="NetworkManager-glib is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:103708"/>
          <criterion comment="NetworkManager-devel is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:103786"/>
          <criterion comment="NetworkManager-gnome is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:103706"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:103718"/>
          <criterion comment="NetworkManager is earlier than 1:0.7.0-9.el5_4" test_ref="oval:org.mitre.oval:tst:102785"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22955" version="77" class="patch">
      <metadata>
        <title>ELSA-2009:1499: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2009:1499-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1499.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2979" ref_url="http://linux.oracle.com/cve/CVE-2009-2979.html" source="CVE"/>
        <reference ref_id="CVE-2009-2980" ref_url="http://linux.oracle.com/cve/CVE-2009-2980.html" source="CVE"/>
        <reference ref_id="CVE-2009-2981" ref_url="http://linux.oracle.com/cve/CVE-2009-2981.html" source="CVE"/>
        <reference ref_id="CVE-2009-2983" ref_url="http://linux.oracle.com/cve/CVE-2009-2983.html" source="CVE"/>
        <reference ref_id="CVE-2009-2985" ref_url="http://linux.oracle.com/cve/CVE-2009-2985.html" source="CVE"/>
        <reference ref_id="CVE-2009-2986" ref_url="http://linux.oracle.com/cve/CVE-2009-2986.html" source="CVE"/>
        <reference ref_id="CVE-2009-2988" ref_url="http://linux.oracle.com/cve/CVE-2009-2988.html" source="CVE"/>
        <reference ref_id="CVE-2009-2990" ref_url="http://linux.oracle.com/cve/CVE-2009-2990.html" source="CVE"/>
        <reference ref_id="CVE-2009-2991" ref_url="http://linux.oracle.com/cve/CVE-2009-2991.html" source="CVE"/>
        <reference ref_id="CVE-2009-2993" ref_url="http://linux.oracle.com/cve/CVE-2009-2993.html" source="CVE"/>
        <reference ref_id="CVE-2009-2994" ref_url="http://linux.oracle.com/cve/CVE-2009-2994.html" source="CVE"/>
        <reference ref_id="CVE-2009-2996" ref_url="http://linux.oracle.com/cve/CVE-2009-2996.html" source="CVE"/>
        <reference ref_id="CVE-2009-2997" ref_url="http://linux.oracle.com/cve/CVE-2009-2997.html" source="CVE"/>
        <reference ref_id="CVE-2009-2998" ref_url="http://linux.oracle.com/cve/CVE-2009-2998.html" source="CVE"/>
        <reference ref_id="CVE-2009-3431" ref_url="http://linux.oracle.com/cve/CVE-2009-3431.html" source="CVE"/>
        <reference ref_id="CVE-2009-3458" ref_url="http://linux.oracle.com/cve/CVE-2009-3458.html" source="CVE"/>
        <reference ref_id="CVE-2009-3459" ref_url="http://linux.oracle.com/cve/CVE-2009-3459.html" source="CVE"/>
        <reference ref_id="CVE-2009-3462" ref_url="http://linux.oracle.com/cve/CVE-2009-3462.html" source="CVE"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a "format bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:22.831-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:58.751-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:55.399-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22955 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:47.881-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:58.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="acroread-plugin is earlier than 0:8.1.7-1.el5" test_ref="oval:org.mitre.oval:tst:103035"/>
          <criterion comment="acroread is earlier than 0:8.1.7-1.el5" test_ref="oval:org.mitre.oval:tst:102496"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22954" version="121" class="patch">
      <metadata>
        <title>ELSA-2010:0770: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2010:0770-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0770.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-1321" ref_url="http://linux.oracle.com/cve/CVE-2010-1321.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3550" ref_url="http://linux.oracle.com/cve/CVE-2010-3550.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3552" ref_url="http://linux.oracle.com/cve/CVE-2010-3552.html" source="CVE"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3554" ref_url="http://linux.oracle.com/cve/CVE-2010-3554.html" source="CVE"/>
        <reference ref_id="CVE-2010-3555" ref_url="http://linux.oracle.com/cve/CVE-2010-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-3556" ref_url="http://linux.oracle.com/cve/CVE-2010-3556.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3558" ref_url="http://linux.oracle.com/cve/CVE-2010-3558.html" source="CVE"/>
        <reference ref_id="CVE-2010-3559" ref_url="http://linux.oracle.com/cve/CVE-2010-3559.html" source="CVE"/>
        <reference ref_id="CVE-2010-3560" ref_url="http://linux.oracle.com/cve/CVE-2010-3560.html" source="CVE"/>
        <reference ref_id="CVE-2010-3561" ref_url="http://linux.oracle.com/cve/CVE-2010-3561.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3563" ref_url="http://linux.oracle.com/cve/CVE-2010-3563.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3566" ref_url="http://linux.oracle.com/cve/CVE-2010-3566.html" source="CVE"/>
        <reference ref_id="CVE-2010-3567" ref_url="http://linux.oracle.com/cve/CVE-2010-3567.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3570" ref_url="http://linux.oracle.com/cve/CVE-2010-3570.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <reference ref_id="CVE-2010-3572" ref_url="http://linux.oracle.com/cve/CVE-2010-3572.html" source="CVE"/>
        <reference ref_id="CVE-2010-3573" ref_url="http://linux.oracle.com/cve/CVE-2010-3573.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:18.776-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:57.766-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:53.759-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22954 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:53.538-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:57.095-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104082"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104312"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104013"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104336"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104285"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.22-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22952" version="109" class="patch">
      <metadata>
        <title>ELSA-2010:0337: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2010:0337-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0337.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-0082" ref_url="http://linux.oracle.com/cve/CVE-2010-0082.html" source="CVE"/>
        <reference ref_id="CVE-2010-0084" ref_url="http://linux.oracle.com/cve/CVE-2010-0084.html" source="CVE"/>
        <reference ref_id="CVE-2010-0085" ref_url="http://linux.oracle.com/cve/CVE-2010-0085.html" source="CVE"/>
        <reference ref_id="CVE-2010-0087" ref_url="http://linux.oracle.com/cve/CVE-2010-0087.html" source="CVE"/>
        <reference ref_id="CVE-2010-0088" ref_url="http://linux.oracle.com/cve/CVE-2010-0088.html" source="CVE"/>
        <reference ref_id="CVE-2010-0089" ref_url="http://linux.oracle.com/cve/CVE-2010-0089.html" source="CVE"/>
        <reference ref_id="CVE-2010-0090" ref_url="http://linux.oracle.com/cve/CVE-2010-0090.html" source="CVE"/>
        <reference ref_id="CVE-2010-0091" ref_url="http://linux.oracle.com/cve/CVE-2010-0091.html" source="CVE"/>
        <reference ref_id="CVE-2010-0092" ref_url="http://linux.oracle.com/cve/CVE-2010-0092.html" source="CVE"/>
        <reference ref_id="CVE-2010-0093" ref_url="http://linux.oracle.com/cve/CVE-2010-0093.html" source="CVE"/>
        <reference ref_id="CVE-2010-0094" ref_url="http://linux.oracle.com/cve/CVE-2010-0094.html" source="CVE"/>
        <reference ref_id="CVE-2010-0095" ref_url="http://linux.oracle.com/cve/CVE-2010-0095.html" source="CVE"/>
        <reference ref_id="CVE-2010-0837" ref_url="http://linux.oracle.com/cve/CVE-2010-0837.html" source="CVE"/>
        <reference ref_id="CVE-2010-0838" ref_url="http://linux.oracle.com/cve/CVE-2010-0838.html" source="CVE"/>
        <reference ref_id="CVE-2010-0839" ref_url="http://linux.oracle.com/cve/CVE-2010-0839.html" source="CVE"/>
        <reference ref_id="CVE-2010-0840" ref_url="http://linux.oracle.com/cve/CVE-2010-0840.html" source="CVE"/>
        <reference ref_id="CVE-2010-0841" ref_url="http://linux.oracle.com/cve/CVE-2010-0841.html" source="CVE"/>
        <reference ref_id="CVE-2010-0842" ref_url="http://linux.oracle.com/cve/CVE-2010-0842.html" source="CVE"/>
        <reference ref_id="CVE-2010-0843" ref_url="http://linux.oracle.com/cve/CVE-2010-0843.html" source="CVE"/>
        <reference ref_id="CVE-2010-0844" ref_url="http://linux.oracle.com/cve/CVE-2010-0844.html" source="CVE"/>
        <reference ref_id="CVE-2010-0845" ref_url="http://linux.oracle.com/cve/CVE-2010-0845.html" source="CVE"/>
        <reference ref_id="CVE-2010-0846" ref_url="http://linux.oracle.com/cve/CVE-2010-0846.html" source="CVE"/>
        <reference ref_id="CVE-2010-0847" ref_url="http://linux.oracle.com/cve/CVE-2010-0847.html" source="CVE"/>
        <reference ref_id="CVE-2010-0848" ref_url="http://linux.oracle.com/cve/CVE-2010-0848.html" source="CVE"/>
        <reference ref_id="CVE-2010-0849" ref_url="http://linux.oracle.com/cve/CVE-2010-0849.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.	NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:54.354-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:56.628-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:52.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22952 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:52.551-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:55.927-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103773"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103841"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103916"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103863"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103791"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.19-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:103159"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22951" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1287: openssh security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>openssh</product>
        </affected>
        <reference ref_id="ELSA-2009:1287-02" ref_url="http://linux.oracle.com/errata/ELSA-2009-1287.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-5161" ref_url="http://linux.oracle.com/cve/CVE-2008-5161.html" source="CVE"/>
        <description>Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T08:57:31.897-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:56.522-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:52.364-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22951 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:49.081-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:55.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssh is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:103223"/>
          <criterion comment="openssh-clients is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:102758"/>
          <criterion comment="openssh-server is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:103248"/>
          <criterion comment="openssh-askpass is earlier than 0:4.3p2-36.el5" test_ref="oval:org.mitre.oval:tst:103264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22950" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0392: libtiff security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2011:0392-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0392.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1167" ref_url="http://linux.oracle.com/cve/CVE-2011-1167.html" source="CVE"/>
        <description>Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:22.573-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:56.405-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:52.233-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22950 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:49.399-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:55.641-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:42:16.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:42:16.448-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:104879"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:104797"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:104672"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:104954"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:104924"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22949" version="93" class="patch">
      <metadata>
        <title>ELSA-2009:1560: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2009:1560-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1560.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2409" ref_url="http://linux.oracle.com/cve/CVE-2009-2409.html" source="CVE"/>
        <reference ref_id="CVE-2009-3728" ref_url="http://linux.oracle.com/cve/CVE-2009-3728.html" source="CVE"/>
        <reference ref_id="CVE-2009-3729" ref_url="http://linux.oracle.com/cve/CVE-2009-3729.html" source="CVE"/>
        <reference ref_id="CVE-2009-3865" ref_url="http://linux.oracle.com/cve/CVE-2009-3865.html" source="CVE"/>
        <reference ref_id="CVE-2009-3866" ref_url="http://linux.oracle.com/cve/CVE-2009-3866.html" source="CVE"/>
        <reference ref_id="CVE-2009-3867" ref_url="http://linux.oracle.com/cve/CVE-2009-3867.html" source="CVE"/>
        <reference ref_id="CVE-2009-3868" ref_url="http://linux.oracle.com/cve/CVE-2009-3868.html" source="CVE"/>
        <reference ref_id="CVE-2009-3869" ref_url="http://linux.oracle.com/cve/CVE-2009-3869.html" source="CVE"/>
        <reference ref_id="CVE-2009-3871" ref_url="http://linux.oracle.com/cve/CVE-2009-3871.html" source="CVE"/>
        <reference ref_id="CVE-2009-3872" ref_url="http://linux.oracle.com/cve/CVE-2009-3872.html" source="CVE"/>
        <reference ref_id="CVE-2009-3873" ref_url="http://linux.oracle.com/cve/CVE-2009-3873.html" source="CVE"/>
        <reference ref_id="CVE-2009-3874" ref_url="http://linux.oracle.com/cve/CVE-2009-3874.html" source="CVE"/>
        <reference ref_id="CVE-2009-3875" ref_url="http://linux.oracle.com/cve/CVE-2009-3875.html" source="CVE"/>
        <reference ref_id="CVE-2009-3876" ref_url="http://linux.oracle.com/cve/CVE-2009-3876.html" source="CVE"/>
        <reference ref_id="CVE-2009-3877" ref_url="http://linux.oracle.com/cve/CVE-2009-3877.html" source="CVE"/>
        <reference ref_id="CVE-2009-3879" ref_url="http://linux.oracle.com/cve/CVE-2009-3879.html" source="CVE"/>
        <reference ref_id="CVE-2009-3880" ref_url="http://linux.oracle.com/cve/CVE-2009-3880.html" source="CVE"/>
        <reference ref_id="CVE-2009-3881" ref_url="http://linux.oracle.com/cve/CVE-2009-3881.html" source="CVE"/>
        <reference ref_id="CVE-2009-3882" ref_url="http://linux.oracle.com/cve/CVE-2009-3882.html" source="CVE"/>
        <reference ref_id="CVE-2009-3883" ref_url="http://linux.oracle.com/cve/CVE-2009-3883.html" source="CVE"/>
        <reference ref_id="CVE-2009-3884" ref_url="http://linux.oracle.com/cve/CVE-2009-3884.html" source="CVE"/>
        <reference ref_id="CVE-2009-3886" ref_url="http://linux.oracle.com/cve/CVE-2009-3886.html" source="CVE"/>
        <description>The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression," aka Bug Id 6870531.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:42.860-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:55.583-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:51.186-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22949 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:51.353-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:54.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.17-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103212"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.17-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103556"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.17-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103224"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.17-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103511"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.17-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:103315"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.17-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:102972"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22948" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0545: ImageMagick security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ImageMagick</product>
        </affected>
        <reference ref_id="ELSA-2012:0545-00" ref_url="http://linux.oracle.com/errata/ELSA-2012-0545.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0247" ref_url="http://linux.oracle.com/cve/CVE-2012-0247.html" source="CVE"/>
        <reference ref_id="CVE-2012-0248" ref_url="http://linux.oracle.com/cve/CVE-2012-0248.html" source="CVE"/>
        <reference ref_id="CVE-2012-0260" ref_url="http://linux.oracle.com/cve/CVE-2012-0260.html" source="CVE"/>
        <description>The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:59.825-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:55.404-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:50.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22948 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:48.531-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:54.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:106174"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:106196"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:105951"/>
          <criterion comment="ImageMagick is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:106175"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-15.el5_8" test_ref="oval:org.mitre.oval:tst:105869"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22947" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0189: ipa-client security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>ipa-client</product>
        </affected>
        <reference ref_id="ELSA-2013:0189-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0189.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5484" ref_url="http://linux.oracle.com/cve/CVE-2012-5484.html" source="CVE"/>
        <description>The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:58.417-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:55.317-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:50.814-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22947 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:49.483-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:54.464-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="ipa-client is earlier than 0:2.1.3-5.el5_9.2" test_ref="oval:org.mitre.oval:tst:106810"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22946" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1377: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2011:1377-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1377.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2483" ref_url="http://linux.oracle.com/cve/CVE-2011-2483.html" source="CVE"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:31.832-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:55.219-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:50.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22946 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:51.616-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:54.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105034"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105123"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105267"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105216"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105113"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105286"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105235"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105115"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:105048"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:104988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105144"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:104975"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:104491"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105238"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105089"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105107"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105326"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105270"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:104884"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105268"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22945" version="42" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1423: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2011:1423-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1423.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0708" ref_url="http://linux.oracle.com/cve/CVE-2011-0708.html" source="CVE"/>
        <reference ref_id="CVE-2011-1148" ref_url="http://linux.oracle.com/cve/CVE-2011-1148.html" source="CVE"/>
        <reference ref_id="CVE-2011-1466" ref_url="http://linux.oracle.com/cve/CVE-2011-1466.html" source="CVE"/>
        <reference ref_id="CVE-2011-1468" ref_url="http://linux.oracle.com/cve/CVE-2011-1468.html" source="CVE"/>
        <reference ref_id="CVE-2011-1469" ref_url="http://linux.oracle.com/cve/CVE-2011-1469.html" source="CVE"/>
        <reference ref_id="CVE-2011-1471" ref_url="http://linux.oracle.com/cve/CVE-2011-1471.html" source="CVE"/>
        <reference ref_id="CVE-2011-1938" ref_url="http://linux.oracle.com/cve/CVE-2011-1938.html" source="CVE"/>
        <reference ref_id="CVE-2011-2202" ref_url="http://linux.oracle.com/cve/CVE-2011-2202.html" source="CVE"/>
        <reference ref_id="CVE-2011-2483" ref_url="http://linux.oracle.com/cve/CVE-2011-2483.html" source="CVE"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:35.680-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:54.742-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:50.012-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22945 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:50.331-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:53.713-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:41:33.009-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:41:33.009-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105333"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105226"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:104527"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105101"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105375"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105384"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105415"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:104923"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105087"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105432"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105412"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:104465"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105430"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105032"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105203"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105092"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105431"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105458"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:104740"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105446"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:105196"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105493"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105018"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105131"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105429"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105505"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105439"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105395"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105474"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105176"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105345"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105337"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:104551"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:104997"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105271"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105510"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105317"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:104985"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105003"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:104728"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105518"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:104549"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105508"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105457"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105299"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105313"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:105209"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22944" version="13" class="patch">
      <metadata>
        <title>ELSA-2009:1452: neon security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>neon</product>
        </affected>
        <reference ref_id="ELSA-2009:1452-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1452.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2473" ref_url="http://linux.oracle.com/cve/CVE-2009-2473.html" source="CVE"/>
        <reference ref_id="CVE-2009-2474" ref_url="http://linux.oracle.com/cve/CVE-2009-2474.html" source="CVE"/>
        <description>neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:32.660-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:54.612-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:49.839-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22944 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:52.774-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:53.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="neon is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:103228"/>
          <criterion comment="neon-devel is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:103016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22943" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0426: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0426-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0426.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0884" ref_url="http://linux.oracle.com/cve/CVE-2012-0884.html" source="CVE"/>
        <reference ref_id="CVE-2012-1165" ref_url="http://linux.oracle.com/cve/CVE-2012-1165.html" source="CVE"/>
        <description>The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:01.182-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:54.474-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:49.652-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22943 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:51.021-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:53.324-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:38:20.462-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:38:20.462-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:105736"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:105803"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:105805"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:106031"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:105536"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:105437"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:105090"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22942" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1132: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus</product>
        </affected>
        <reference ref_id="ELSA-2011:1132-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1132.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2200" ref_url="http://linux.oracle.com/cve/CVE-2011-2200.html" source="CVE"/>
        <description>The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:25.036-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:54.365-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:49.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22942 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:53.180-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:53.150-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:37:35.103-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:37:35.103-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:105155"/>
            <criterion comment="dbus is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:105067"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:105102"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:105031"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:105117"/>
            <criterion comment="dbus is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:104860"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:105111"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:104989"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:105129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22941" version="50" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0860: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2011:0860-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0860.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0863" ref_url="http://linux.oracle.com/cve/CVE-2011-0863.html" source="CVE"/>
        <reference ref_id="CVE-2011-0864" ref_url="http://linux.oracle.com/cve/CVE-2011-0864.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0868" ref_url="http://linux.oracle.com/cve/CVE-2011-0868.html" source="CVE"/>
        <reference ref_id="CVE-2011-0869" ref_url="http://linux.oracle.com/cve/CVE-2011-0869.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:10.408-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:53.860-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:48.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22941 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:50.750-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:52.543-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:36:40.498-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:36:40.498-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108791"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108746"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109057"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108953"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109003"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109027"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109043"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108290"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108934"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108976"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108928"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22940" version="49" class="patch">
      <metadata>
        <title>ELSA-2010:0046: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2010:0046-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0046.html" source="VENDOR"/>
        <reference ref_id="CVE-2006-6304" ref_url="http://linux.oracle.com/cve/CVE-2006-6304.html" source="CVE"/>
        <reference ref_id="CVE-2009-2910" ref_url="http://linux.oracle.com/cve/CVE-2009-2910.html" source="CVE"/>
        <reference ref_id="CVE-2009-3080" ref_url="http://linux.oracle.com/cve/CVE-2009-3080.html" source="CVE"/>
        <reference ref_id="CVE-2009-3556" ref_url="http://linux.oracle.com/cve/CVE-2009-3556.html" source="CVE"/>
        <reference ref_id="CVE-2009-3889" ref_url="http://linux.oracle.com/cve/CVE-2009-3889.html" source="CVE"/>
        <reference ref_id="CVE-2009-3939" ref_url="http://linux.oracle.com/cve/CVE-2009-3939.html" source="CVE"/>
        <reference ref_id="CVE-2009-4020" ref_url="http://linux.oracle.com/cve/CVE-2009-4020.html" source="CVE"/>
        <reference ref_id="CVE-2009-4021" ref_url="http://linux.oracle.com/cve/CVE-2009-4021.html" source="CVE"/>
        <reference ref_id="CVE-2009-4138" ref_url="http://linux.oracle.com/cve/CVE-2009-4138.html" source="CVE"/>
        <reference ref_id="CVE-2009-4141" ref_url="http://linux.oracle.com/cve/CVE-2009-4141.html" source="CVE"/>
        <reference ref_id="CVE-2009-4272" ref_url="http://linux.oracle.com/cve/CVE-2009-4272.html" source="CVE"/>
        <description>A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and trigger a routing "emergency" in which a hash chain is too long.  NOTE: this is related to an issue in the Linux kernel before 2.6.31, when the kernel routing cache is disabled, involving an uninitialized pointer and a panic.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:57.103-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:53.321-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:48.177-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22940 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:48.233-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:51.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103512"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103519"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103626"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103282"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103345"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103509"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103218"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103013"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103392"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103539"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103480"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:103164"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22939" version="29" class="patch">
      <metadata>
        <title>ELSA-2010:0429: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2010:0429-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0429.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-4136" ref_url="http://linux.oracle.com/cve/CVE-2009-4136.html" source="CVE"/>
        <reference ref_id="CVE-2010-0442" ref_url="http://linux.oracle.com/cve/CVE-2010-0442.html" source="CVE"/>
        <reference ref_id="CVE-2010-0733" ref_url="http://linux.oracle.com/cve/CVE-2010-0733.html" source="CVE"/>
        <reference ref_id="CVE-2010-1169" ref_url="http://linux.oracle.com/cve/CVE-2010-1169.html" source="CVE"/>
        <reference ref_id="CVE-2010-1170" ref_url="http://linux.oracle.com/cve/CVE-2010-1170.html" source="CVE"/>
        <reference ref_id="CVE-2010-1975" ref_url="http://linux.oracle.com/cve/CVE-2010-1975.html" source="CVE"/>
        <description>PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:06:05.521-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:52.931-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:47.727-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22939 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:48.731-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:51.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103692"/>
          <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103709"/>
          <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103817"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103983"/>
          <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103351"/>
          <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103803"/>
          <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103945"/>
          <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103161"/>
          <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103976"/>
          <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:103986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22938" version="6" class="patch">
      <metadata>
        <title>ELSA-2009:1619: dstat security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>dstat</product>
        </affected>
        <reference ref_id="ELSA-2009:1619-01" ref_url="http://linux.oracle.com/errata/ELSA-2009-1619.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3894" ref_url="http://linux.oracle.com/cve/CVE-2009-3894.html" source="CVE"/>
        <description>Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or (2) a certain subdirectory of the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:00:28.253-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:52.832-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:47.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22938 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:51.731-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:51.378-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criterion comment="dstat is earlier than 0:0.6.6-3.el5_4.1" test_ref="oval:org.mitre.oval:tst:102823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22937" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0607: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2010:0607-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0607.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1797" ref_url="http://linux.oracle.com/cve/CVE-2010-1797.html" source="CVE"/>
        <description>Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:05:59.508-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:52.733-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:47.494-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22937 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:50.618-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:51.254-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="freetype is earlier than 0:2.2.1-26.el5_5" test_ref="oval:org.mitre.oval:tst:104186"/>
          <criterion comment="freetype-demos is earlier than 0:2.2.1-26.el5_5" test_ref="oval:org.mitre.oval:tst:104105"/>
          <criterion comment="freetype-devel is earlier than 0:2.2.1-26.el5_5" test_ref="oval:org.mitre.oval:tst:104234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22936" version="54" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0144: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0144-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0144.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0744" ref_url="http://linux.oracle.com/cve/CVE-2013-0744.html" source="CVE"/>
        <reference ref_id="CVE-2013-0746" ref_url="http://linux.oracle.com/cve/CVE-2013-0746.html" source="CVE"/>
        <reference ref_id="CVE-2013-0748" ref_url="http://linux.oracle.com/cve/CVE-2013-0748.html" source="CVE"/>
        <reference ref_id="CVE-2013-0750" ref_url="http://linux.oracle.com/cve/CVE-2013-0750.html" source="CVE"/>
        <reference ref_id="CVE-2013-0753" ref_url="http://linux.oracle.com/cve/CVE-2013-0753.html" source="CVE"/>
        <reference ref_id="CVE-2013-0754" ref_url="http://linux.oracle.com/cve/CVE-2013-0754.html" source="CVE"/>
        <reference ref_id="CVE-2013-0758" ref_url="http://linux.oracle.com/cve/CVE-2013-0758.html" source="CVE"/>
        <reference ref_id="CVE-2013-0759" ref_url="http://linux.oracle.com/cve/CVE-2013-0759.html" source="CVE"/>
        <reference ref_id="CVE-2013-0762" ref_url="http://linux.oracle.com/cve/CVE-2013-0762.html" source="CVE"/>
        <reference ref_id="CVE-2013-0766" ref_url="http://linux.oracle.com/cve/CVE-2013-0766.html" source="CVE"/>
        <reference ref_id="CVE-2013-0767" ref_url="http://linux.oracle.com/cve/CVE-2013-0767.html" source="CVE"/>
        <reference ref_id="CVE-2013-0769" ref_url="http://linux.oracle.com/cve/CVE-2013-0769.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:04.327-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:52.242-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:46.833-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22936 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:49.284-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:50.684-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T15:35:36.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T15:35:36.869-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:107011"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:106949"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:107107"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:106692"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:106977"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:107032"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22935" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0659: httpd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2010:0659-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0659.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1452" ref_url="http://linux.oracle.com/cve/CVE-2010-1452.html" source="CVE"/>
        <reference ref_id="CVE-2010-2791" ref_url="http://linux.oracle.com/cve/CVE-2010-2791.html" source="CVE"/>
        <description>mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.  NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:08:20.802-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:52.118-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:46.639-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22935 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:52.140-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:50.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:104279"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:103734"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:103813"/>
          <criterion comment="httpd is earlier than 0:2.2.3-43.el5_5.3" test_ref="oval:org.mitre.oval:tst:104266"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22934" version="21" class="patch">
      <metadata>
        <title>ELSA-2010:0088: kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <product>kvm</product>
        </affected>
        <reference ref_id="ELSA-2010:0088-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0088.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-0297" ref_url="http://linux.oracle.com/cve/CVE-2010-0297.html" source="CVE"/>
        <reference ref_id="CVE-2010-0298" ref_url="http://linux.oracle.com/cve/CVE-2010-0298.html" source="CVE"/>
        <reference ref_id="CVE-2010-0306" ref_url="http://linux.oracle.com/cve/CVE-2010-0306.html" source="CVE"/>
        <reference ref_id="CVE-2010-0309" ref_url="http://linux.oracle.com/cve/CVE-2010-0309.html" source="CVE"/>
        <description>The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure, which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:03:47.922-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:03:51.918-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:46.270-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22934 - optimisation of Oracle Linux content" date="2014-05-05T17:57:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:58:52.961-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:02:50.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kvm-qemu-img is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:103527"/>
          <criterion comment="kvm is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:103698"/>
          <criterion comment="kmod-kvm is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:102975"/>
          <criterion comment="kvm-tools is earlier than 0:83-105.el5_4.22" test_ref="oval:org.mitre.oval:tst:103088"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22932" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:0374: thunderbird security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0374-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0374.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
This erratum blacklists a small number of HTTPS certificates. (BZ#689430)
This update also fixes the following bug:
* The RHSA-2011:0312 and RHSA-2011:0311 updates introduced a regression,
preventing some Java content and plug-ins written in Java from loading.
With this update, the Java content and plug-ins work as expected.
(BZ#683076)
All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:11:11.058-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T